Path Traversal Vulnerability in Zarf Native Packager Manager for Kubernetes
CVE-2026-29064
8.2HIGH
What is CVE-2026-29064?
A path traversal vulnerability identified in the Zarf Native Packager Manager for Kubernetes impacts versions from 0.54.0 to before 0.73.1. This vulnerability occurs during the archive extraction process, allowing a specially crafted Zarf package to create symbolic links that point outside the intended destination directory. Consequently, this can lead to arbitrary file read or write operations on the system processing the malicious package, posing significant security risks. The issue has been rectified in version 0.73.1.
Affected Version(s)
zarf >= 0.54.0, < 0.73.1
