Zarf
Lfprojects · 2 CVEs
CVE-2026-40090
HIGH
Zarf has a Path Traversal via Malicious Package Metadata.Name — Arbitrary File Write
Apr 14, 2026
CVE-2026-29064
HIGH
Zarf: Symlink targets in archives are not validated against destination directory
Mar 6, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-40090 | Zarf has a Path Traversal via Malicious Package Metadata.Name — Arbitrary File Write | HIGH | 0.39% | Apr 14, 2026 |
| CVE-2026-29064 | Zarf: Symlink targets in archives are not validated against destination directory | HIGH | 0.23% | Mar 6, 2026 |
Showing 1 to 2 of 2 CVEs