Junglewise Threat Intelligence

CVE-2026-49248: OneDev arbitrary file write via absolute path symlink in TarUtils

CVE-2026-49248 · Severity: info · CVSS 8.3 · Published 2026-06-18

Technologies: OneDev. Vendors: OneDev.

Executive brief

OneDev, an open-source Git server with CI/CD capabilities, contains a vulnerability that allows users with permission to edit CI/CD jobs to write files to any location on the server. By uploading a specially crafted archive file, an attacker can bypass security restrictions to overwrite critical system files or configuration. This can lead to a complete takeover of the server and potential remote code execution, compromising all hosted code and customer data.

Technical details

A symlink following vulnerability exists in OneDev's TarUtils.untar() component due to improper validation of TAR archive entries. While a previous fix (CVE-2021-21251) blocked directory traversal using '..' segments, it failed to account for absolute paths in symbolic link targets. An attacker with CI Job write access can craft a TAR archive containing a symlink pointing to an absolute path on the server, followed by a file entry that traverses that symlink. This allows for arbitrary file writes on the server host, which can be leveraged for Remote Code Execution (RCE). The issue is resolved in version 15.0.7.

Affected products

  • theonedev OneDev <= 15.0.6

Timeline

  • 2026-05-24: advisory: GitHub Security Advisory published
  • 2026-06-18: disclosed: CVE published to NVD
  • 2026-05-24: patched: Fixed in version 15.0.7

References

Related threats