ZeroHour

CVE-2026-29064

PoC
CVSS 3.1
8.2 high
EPSS
<1%p13
Published
()
Modified
Description

Zarf is an Airgap Native Packager Manager for Kubernetes. From version 0.54.0 to before version 0.73.1, a path traversal vulnerability in archive extraction allows a specifically crafted Zarf package to create symlinks pointing outside the destination directory, enabling arbitrary file read or write on the system processing the package. This issue has been patched in version 0.73.1.

Vendors
lfprojects
Products
zarf
Weakness
CWE-22
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.