Path Traversal Vulnerability in Zarf Native Packager Manager for Kubernetes
CVE-2026-29064

8.2HIGH

Key Information:

Vendor

Zarf-dev

Status
Vendor
CVE Published:
6 March 2026

What is CVE-2026-29064?

A path traversal vulnerability identified in the Zarf Native Packager Manager for Kubernetes impacts versions from 0.54.0 to before 0.73.1. This vulnerability occurs during the archive extraction process, allowing a specially crafted Zarf package to create symbolic links that point outside the intended destination directory. Consequently, this can lead to arbitrary file read or write operations on the system processing the malicious package, posing significant security risks. The issue has been rectified in version 0.73.1.

Affected Version(s)

zarf >= 0.54.0, < 0.73.1

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.