CVE-2026-73030: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in frostming unearth
unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. Attackers can supply malicious tar archives with symlink members or traversal sequences to write files to arbitrary filesystem locations accessible to the process.
AI Analysis
Technical Summary
The vulnerability in unearth through version 0.18.2 arises from improper limitation of a pathname to a restricted directory due to failure to normalize paths in the is_within_directory function. This allows path traversal attacks where attackers can supply malicious tar archives containing symlink members or traversal sequences (../) that bypass directory containment checks, potentially writing files outside the intended extraction directory. The issue was addressed in commit 6c78164, which corrects the path normalization and validation logic.
Potential Impact
Successful exploitation allows an attacker to write files to arbitrary filesystem locations accessible to the unearth process. This can lead to unauthorized file creation or modification, potentially enabling further compromise depending on the privileges of the process running unearth. The CVSS 4.0 score is 7.2 (high severity), indicating a significant risk if exploited.
Mitigation Recommendations
A fix is available and was introduced in commit 6c78164. Users should upgrade to a version of unearth that includes this commit or later to remediate the vulnerability. No official patch version number is provided, so users should verify the presence of the fix in their version. Until patched, avoid processing untrusted tar archives with unearth.
CVE-2026-73030: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in frostming unearth
Description
unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. Attackers can supply malicious tar archives with symlink members or traversal sequences to write files to arbitrary filesystem locations accessible to the process.
CVSS v4.0
Score 7.2high
Affected software
frostming
unearth
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in unearth through version 0.18.2 arises from improper limitation of a pathname to a restricted directory due to failure to normalize paths in the is_within_directory function. This allows path traversal attacks where attackers can supply malicious tar archives containing symlink members or traversal sequences (../) that bypass directory containment checks, potentially writing files outside the intended extraction directory. The issue was addressed in commit 6c78164, which corrects the path normalization and validation logic.
Potential Impact
Successful exploitation allows an attacker to write files to arbitrary filesystem locations accessible to the unearth process. This can lead to unauthorized file creation or modification, potentially enabling further compromise depending on the privileges of the process running unearth. The CVSS 4.0 score is 7.2 (high severity), indicating a significant risk if exploited.
Mitigation Recommendations
A fix is available and was introduced in commit 6c78164. Users should upgrade to a version of unearth that includes this commit or later to remediate the vulnerability. No official patch version number is provided, so users should verify the presence of the fix in their version. Until patched, avoid processing untrusted tar archives with unearth.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-10T18:48:59.022Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a7a3406bf8831d5397b035e
Added to database: 08/10/2026, 20:26:46 UTC
Last enriched: 08/10/2026, 20:41:20 UTC
Last updated: 09/23/2026, 14:28:57 UTC
Views: 55
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.