PatchSiren

composefs CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH composefs CVE published 2026-08-10

CVE-2026-70622

CVE-2026-70622 is a symlink escape vulnerability in the tar-rs library, specifically in the Builder::append_dir_all() function. This vulnerability allows attackers to read files outside the intended source root directory by creating symlinks in a controlled directory. When a privileged process archives an untrusted directory, the function follows symlinks without verifying that the resolved targets remain [truncated]