Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 11 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Composefs
Composefs tar-rs |
|
| Vendors & Products |
Composefs
Composefs tar-rs |
Tue, 11 Aug 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function that allows attackers to read files outside the intended source root directory by planting symlinks in an attacker-controlled directory. When a privileged process archives an untrusted directory, the function follows symlinks without verifying that resolved targets remain within the source root, causing out-of-bounds files to be included in the archive as regular files and disclosed to the attacker. | |
| Title | tar-rs 0.4.11 - 0.4.46 Symlink Escape via append_dir_all() | |
| Weaknesses | CWE-59 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-11T02:01:40.553Z
Reserved: 2026-08-04T20:17:18.296Z
Link: CVE-2026-70622
Updated: 2026-08-11T02:01:36.299Z
Status : Received
Published: 2026-08-10T18:18:50.610
Modified: 2026-08-11T03:18:00.540
Link: CVE-2026-70622
No data.
OpenCVE Enrichment
Updated: 2026-08-11T14:22:28Z
-
CWE-59
Improper Link Resolution Before File Access ('Link Following')