Junglewise Threat Intelligence

CVE-2026-29064: GO-2026-4636 - Zarf's symlink targets in archives are not validated against destination directory in github.com/zarf-dev/zarf

CVE-2026-29064 · Severity: low · CVSS 3.1 · Published 2026-03-10

Vendors: Go.

Executive brief

Zarf's symlink targets in archives are not validated against destination directory in github.com/zarf-dev/zarf

Affected products

  • Go github.com/zarf-dev/zarf
  • Go github.com/zarf-dev/zarf/src/pkg/archive

Related threats