No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 11 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. Attackers can supply malicious tar archives with symlink members or traversal sequences to write files to arbitrary filesystem locations accessible to the process. | |
| Title | unearth 0.18.2 Path Traversal via Unnormalized Paths and Symlink Escape | |
| First Time appeared |
Frostming
Frostming unearth |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:frostming:unearth:0.10.0:*:*:*:*:python:*:* cpe:2.3:a:frostming:unearth:0.11.0:*:*:*:*:python:*:* cpe:2.3:a:frostming:unearth:0.11.1:*:*:*:*:python:*:* cpe:2.3:a:frostming:unearth:0.11.2:*:*:*:*:python:*:* cpe:2.3:a:frostming:unearth:0.12.0:*:*:*:*:python:*:* cpe:2.3:a:frostming:unearth:0.12.1:*:*:*:*:python:*:* cpe:2.3:a:frostming:unearth:0.5.2:*:*:*:*:python:*:* cpe:2.3:a:frostming:unearth:0.6.0:*:*:*:*:python:*:* cpe:2.3:a:frostming:unearth:0.6.1:*:*:*:*:python:*:* cpe:2.3:a:frostming:unearth:0.6.2:*:*:*:*:python:*:* cpe:2.3:a:frostming:unearth:0.6.3:*:*:*:*:python:*:* cpe:2.3:a:frostming:unearth:0.7.0:*:*:*:*:python:*:* cpe:2.3:a:frostming:unearth:0.7.1:*:*:*:*:python:*:* cpe:2.3:a:frostming:unearth:0.7.2:*:*:*:*:python:*:* cpe:2.3:a:frostming:unearth:0.8.0:*:*:*:*:python:*:* cpe:2.3:a:frostming:unearth:0.8.1:*:*:*:*:python:*:* cpe:2.3:a:frostming:unearth:0.9.0:*:*:*:*:python:*:* cpe:2.3:a:frostming:unearth:0.9.1:*:*:*:*:python:*:* cpe:2.3:a:frostming:unearth:0.9.2:*:*:*:*:python:*:* cpe:2.3:a:frostming:unearth:0.9.3:*:*:*:*:python:*:* |
|
| Vendors & Products |
Frostming
Frostming unearth |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-11T17:16:13.975Z
Reserved: 2026-08-10T18:48:59.022Z
Link: CVE-2026-73030
Updated: 2026-08-11T17:16:08.618Z
Status : Received
Published: 2026-08-10T21:17:26.450
Modified: 2026-08-11T18:18:25.960
Link: CVE-2026-73030
No data.
OpenCVE Enrichment
Updated: 2026-08-11T03:15:05Z