CVE-2026-29064 Details
Description
Zarf is an Airgap Native Packager Manager for Kubernetes. From version 0.54.0 to before version 0.73.1, a path traversal vulnerability in archive extraction allows a specifically crafted Zarf package to create symlinks pointing outside the destination directory, enabling arbitrary file read or write on the system processing the package. This issue has been patched in version 0.73.1.
A path traversal vulnerability has been identified in Zarf, a package manager for Kubernetes, affecting versions 0.54.0 prior to 0.73.1. The vulnerability arises during archive extraction, where a maliciously crafted Zarf package can create symlinks that point outside the intended destination directory. This flaw enables arbitrary file read or write operations on the system processing the package. The issue has been patched in version 0.73.1.
Users should upgrade to Zarf version 0.73.1. If an immediate upgrade is not possible, only process Zarf packages from trusted sources until the update can be applied.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/zarf-dev/zarf/releases/tag/v0.73.1 | [email protected] | ProductRelease Notes |
| https://github.com/zarf-dev/zarf/security/advisories/GHSA-hcm4-6hpj-vghm | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| lfprojects zarf | >= 0.54.0, < 0.73.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 11, 2026 | Initial Analysis | [email protected] |
| Mar 6, 2026 | New CVE Received | [email protected] |