unearth through 0.18.2, fixed in commit 6c78164, contains...
High severity
Unreviewed
Published
Aug 10, 2026
to the GitHub Advisory Database
•
Updated Aug 10, 2026
Description
Published by the National Vulnerability Database
Aug 10, 2026
Published to the GitHub Advisory Database
Aug 10, 2026
Last updated
Aug 10, 2026
unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. Attackers can supply malicious tar archives with symlink members or traversal sequences to write files to arbitrary filesystem locations accessible to the process.
References