DEBIAN-CVE-2026-73030

Source
https://security-tracker.debian.org/tracker/CVE-2026-73030
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-73030.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-73030
Upstream
Published
2026-08-10T21:17:26Z
Modified
2026-09-14T17:03:32Z
Severity
  • 7.2 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. Attackers can supply malicious tar archives with symlink members or traversal sequences to write files to arbitrary filesystem locations accessible to the process.

References

Affected packages

Debian:12 / unearth

Package

Name
unearth
Purl
pkg:deb/debian/unearth?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.7.2+ds-2
0.8.1+ds-1~exp1
0.9.1+ds-1
0.9.2+ds1-1
0.10.0+ds1-1
0.11.0+ds-1
0.12.1+ds-1
0.14.0+ds-1
0.15.0+ds-1
0.15.1+ds-1
0.15.2+ds-1
0.15.3+ds-1
0.15.4+ds-1
0.15.5+ds-1
0.16.0+ds-1
0.16.1-1
0.17.1-1
0.17.2-1
0.17.3-1
0.17.5-1
0.18.1-1
0.18.2-1
0.18.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-73030.json"

Debian:13 / unearth

Package

Name
unearth
Purl
pkg:deb/debian/unearth?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.17.5-1
0.18.1-1
0.18.2-1
0.18.3-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-73030.json"

Debian:14 / unearth

Package

Name
unearth
Purl
pkg:deb/debian/unearth?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.18.3-1

Affected versions

0.*
0.17.5-1
0.18.1-1
0.18.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-73030.json"