Executive brief
Zarf's symlink targets in archives are not validated against destination directory in github.com/zarf-dev/zarf
Affected products
- Go github.com/zarf-dev/zarf
- Go github.com/zarf-dev/zarf/src/pkg/archive
Junglewise Threat Intelligence
CVE-2026-29064 · Severity: low · CVSS 3.1 · Published 2026-03-10
Vendors: Go.
Zarf's symlink targets in archives are not validated against destination directory in github.com/zarf-dev/zarf