Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-73030: unearth could let attackers write files anywhere
CVE-2026-73030 · published 1 month ago
Summary
The unearth tool (versions up to 0.18.2) does not correctly clean up file paths before checking them, so specially crafted archive files can include ".." sequences or symbolic links that escape the intended folder. This allows an attacker to place files in any location the program can access, potentially overwriting important data. Update to the latest version of unearth where the path handling has been corrected.
What to do
- Update debian unearth to version 0.18.3-1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | frostming | unearth | <= 0.18.2 |
| Debian:12 | debian | unearth | All versions |
| Debian:13 | debian | unearth | All versions |
| Debian:14 | debian | unearth |
< 0.18.3-1 Fix: upgrade to 0.18.3-1
|
| Ubuntu:24.04:LTS | canonical | unearth | All versions |
Original advisory text
unearth 0.18.2 Path Traversal via Unnormalized Paths and Symlink Escape
unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. Attackers can supply malicious tar archives with symlink members or traversal sequences to write files to arbitrary filesystem locations accessible to the process.
References
- https://github.com/frostming/unearth/issues/180 Third Party Advisory
- https://github.com/frostming/unearth/pull/181 Third Party Advisory
- https://github.com/frostming/unearth/commit/6c78164e7bfa28b8b3d6f247b87e560692e3... Patch
- https://www.vulncheck.com/advisories/unearth-path-traversal-via-unnormalized-pat... Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-73030 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-73030 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-73030 Third Party Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73030... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-73030 Vendor Advisory
- https://github.com/frostming/unearth Product
Internet-facing
60 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker partial control
Severity
9.1
Critical
Type
CWE-22Path Traversal
Timeline
Published10 Aug 2026
Updated1 Oct 2026
First seen10 Aug 2026
Sources
CVE-2026-73030 · NVD
CVE-2026-73030 · MITRE
DEBIAN-CVE-2026-73030 · OSV
UBUNTU-CVE-2026-73030 · OSV
CVE-2026-73030 · OSV
Track software like this
Free during beta