PatchSiren

frostming CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH frostming CVE published 2026-08-10

CVE-2026-73030

A path traversal vulnerability exists in unearth through version 0.18.2, fixed in commit 6c78164. The is_within_directory function fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. This could allow attackers to write files to arbitrary filesystem locations accessible to the process by supplying malicious tar archives with symlink members or traversal sequences.