Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Domwhewell-Sage

Researcher fromBlack Lantern Security
#50653of 56,330
5.3Total CVSS
Vulnerabilities · 1
PT-2026-50560
5.3
2026-06-17
Gnu · Gnu Tar · CVE-2026-12565
**Name of the Vulnerable Software and Affected Versions** The product name cannot be determined (affected versions not specified) **Description** The `unarchive` internal module's archive extraction commands lack code-level validation for extracted file paths. This causes the module to rely on the behavior of external tools, such as GNU tar, which varies across platforms. This path traversal issue allows a malicious archive to write files outside the intended extraction directory on systems using GNU tar versions prior to 1.34. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.