CVE-2026-24909

vlt before 1.0.0-rc.10 mishandles path sanitization for tar, leading to path traversal during extraction.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) vlt anterior a 1.0.0-rc.10 maneja incorrectamente la sanitización de rutas para tar, lo que lleva a un salto de ruta durante la extracción.

27 Jan 2026, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-27 23:15

Updated : 2026-04-15 00:35


NVD link : CVE-2026-24909

Mitre link : CVE-2026-24909

CVE.ORG link : CVE-2026-24909


JSON object : View

Products Affected

No product.

CWE
CWE-23

Relative Path Traversal