CVE-2026-24909

Source
https://cve.org/CVERecord?id=CVE-2026-24909
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-24909.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-24909
Aliases
Published
2026-01-27T23:15:50.680Z
Modified
2026-03-13T11:36:59.682854Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

vlt before 1.0.0-rc.10 mishandles path sanitization for tar, leading to path traversal during extraction.

References

Affected packages

Git / github.com/vltpkg/vltpkg

Affected ranges

Type
GIT
Repo
https://github.com/vltpkg/vltpkg
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.0.0-rc.10"
        }
    ]
}

Affected versions

v0.*
v0.0.0-1
v0.0.0-10
v0.0.0-11
v0.0.0-12
v0.0.0-13
v0.0.0-14
v0.0.0-15
v0.0.0-16
v0.0.0-17
v0.0.0-18
v0.0.0-19
v0.0.0-2
v0.0.0-20
v0.0.0-21
v0.0.0-22
v0.0.0-23
v0.0.0-24
v0.0.0-25
v0.0.0-26
v0.0.0-27
v0.0.0-28
v0.0.0-29
v0.0.0-3
v0.0.0-30
v0.0.0-31
v0.0.0-32
v0.0.0-4
v0.0.0-5
v0.0.0-6
v0.0.0-7
v0.0.0-8
v0.0.0-9
v1.*
v1.0.0-rc.1
v1.0.0-rc.2
v1.0.0-rc.3
v1.0.0-rc.4
v1.0.0-rc.5
v1.0.0-rc.6
v1.0.0-rc.7
v1.0.0-rc.8
v1.0.0-rc.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-24909.json"