HIGH
composefs
CVE published 2026-08-10
CVE-2026-70622
CVE-2026-70622 is a symlink escape vulnerability in the tar-rs library, specifically in the Builder::append_dir_all() function. This vulnerability allows attackers to read files outside the intended source root directory by creating symlinks in a controlled directory. When a privileged process archives an untrusted directory, the function follows symlinks without verifying that the resolved targets remain [truncated]