PT-2026-69945 · Pypi · Unearth

·

CVE-2026-73030

·

Published

2026-08-10

·

Updated

2026-08-18

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions unearth versions prior to 0.18.2
Description A path traversal issue exists in the is within directory() function, which fails to normalize paths before validation. This allows ../ sequences to bypass directory containment checks. An attacker can use malicious tar archives containing symlink members or traversal sequences to write files to arbitrary filesystem locations accessible to the process.
Recommendations Update to the version containing commit 6c78164.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73030
OPENSUSE-SU-2026:11541-1
OPENSUSE-SU-2026:21606-1

Affected Products

Unearth