Onedev · Onedev · CVE-2026-49248
**Name of the Vulnerable Software and Affected Versions**
OneDev versions prior to 15.0.7
**Description**
An arbitrary file write issue exists due to symlink path traversal. The `TarUtils.untar()` function creates symbolic links using the `getLinkName()` TAR entry without validating if the target is an absolute path. A subsequent file entry within the same archive can traverse this symlink to write to arbitrary server-side locations. This can be exploited by any authenticated user with CI Job write access without requiring administrator interaction.
**Recommendations**
Update to version 15.0.7.