Junglewise Threat Intelligence

CVE-2026-33056: RUSTSEC-2026-0067 - `unpack_in` can chmod arbitrary directories by following symlinks

CVE-2026-33056 · Severity: medium · CVSS 4 · Published 2026-03-19

Technologies: tar (crates.io). Vendors: crates.io.

Executive brief

`unpack_in` can chmod arbitrary directories by following symlinks

Affected products

  • crates.io tar

Related threats