Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-73030: unearth could let attackers write files anywhere

CVE-2026-73030 · published 1 month ago
Summary

The unearth tool (versions up to 0.18.2) does not correctly clean up file paths before checking them, so specially crafted archive files can include ".." sequences or symbolic links that escape the intended folder. This allows an attacker to place files in any location the program can access, potentially overwriting important data. Update to the latest version of unearth where the path handling has been corrected.

What to do
  • Update debian unearth to version 0.18.3-1.
Affected software
Ecosystem VendorProductAffected versions
– frostming unearth <= 0.18.2
Debian:12 debian unearth All versions
Debian:13 debian unearth All versions
Debian:14 debian unearth < 0.18.3-1
Fix: upgrade to 0.18.3-1
Ubuntu:24.04:LTS canonical unearth All versions
Original advisory text
unearth 0.18.2 Path Traversal via Unnormalized Paths and Symlink Escape
unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. Attackers can supply malicious tar archives with symlink members or traversal sequences to write files to arbitrary filesystem locations accessible to the process.
Fix within
Internet-facing 60 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker partial control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-22Path Traversal
Timeline
Published10 Aug 2026
Updated1 Oct 2026
First seen10 Aug 2026
Track software like this
Free during beta