{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-07-02T19:04:28.580","vulnerabilities":[{"cve":{"id":"CVE-2026-29064","sourceIdentifier":"security-advisories@github.com","published":"2026-03-06T17:16:34.003","lastModified":"2026-06-17T10:29:32.193","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Zarf is an Airgap Native Packager Manager for Kubernetes. From version 0.54.0 to before version 0.73.1, a path traversal vulnerability in archive extraction allows a specifically crafted Zarf package to create symlinks pointing outside the destination directory, enabling arbitrary file read or write on the system processing the package. This issue has been patched in version 0.73.1."},{"lang":"es","value":"Zarf es un gestor de paquetes nativo Airgap para Kubernetes. Desde la versión 0.54.0 hasta antes de la versión 0.73.1, una vulnerabilidad de salto de ruta en la extracción de archivos permite que un paquete Zarf específicamente diseñado cree enlaces simbólicos apuntando fuera del directorio de destino, lo que permite la lectura o escritura arbitraria de archivos en el sistema que procesa el paquete. Este problema ha sido parcheado en la versión 0.73.1."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"zarf-dev","product":"zarf","versions":[{"version":">= 0.54.0, < 0.73.1","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N","baseScore":8.2,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":5.8}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-03-06T19:31:13.440330Z","id":"CVE-2026-29064","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:lfprojects:zarf:*:*:*:*:*:*:*:*","versionStartIncluding":"0.54.0","versionEndExcluding":"0.73.1","matchCriteriaId":"52E336CB-084F-475A-A9D2-146BC4C01887"}]}]}],"references":[{"url":"https://github.com/zarf-dev/zarf/releases/tag/v0.73.1","source":"security-advisories@github.com","tags":["Product","Release Notes"]},{"url":"https://github.com/zarf-dev/zarf/security/advisories/GHSA-hcm4-6hpj-vghm","source":"security-advisories@github.com","tags":["Exploit","Vendor Advisory"]}]}}]}