PT-2026-32968 · Zarf · Zarf

CVE-2026-40090

·

Published

2026-04-14

·

Updated

2026-07-30

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions Zarf versions 0.23.0 through 0.74.1
Description An arbitrary file write issue exists in the 'zarf package inspect sbom' and 'zarf package inspect documentation' subcommands. These subcommands construct output file paths by joining a user-controlled output directory with the Metadata.Name field read from the package's zarf.yaml manifest. An attacker can modify this field to include absolute paths or path traversal sequences, such as '../../etc/cron.d/malicious', allowing them to write attacker-controlled content to arbitrary filesystem locations based on the permissions of the user executing the command.
Recommendations Update to version 0.74.2. Avoid inspecting unsigned packages.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40090
GHSA-PJ97-4P9W-GX3Q
GO-2026-5542
OPENSUSE-SU-2026:21483-1

Affected Products

Zarf