CVE-2026-24909

vlt before 1.0.0-rc.10 mishandles path sanitization for tar, leading to path traversal during extraction.
Configurations

No configuration.

History

27 Jan 2026, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-27 23:15

Updated : 2026-01-29 16:31


NVD link : CVE-2026-24909

Mitre link : CVE-2026-24909

CVE.ORG link : CVE-2026-24909


JSON object : View

Products Affected

No product.

CWE
CWE-23

Relative Path Traversal