CVE-2026-6968 Details
Description
Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated signing authority to write files outside intended output directories via absolute target names in copy_target/link_target, symlinked parent directories in save_target, or symlinked metadata filenames in SignedRole::write, because write paths trust the joined destination path without post-resolution containment verification. We recommend you upgrade to tough-v0.22.0 / tuftool-v0.15.0.
A path traversal vulnerability has been identified in the AWS Tough library and its command-line utility, Tuftool, prior to versions 0.22.0 and 0.15.0 respectively. This vulnerability allows remote authenticated users with delegated signing authority to write files outside of the intended output directories. The issue arises from incomplete path traversal fixes, where absolute target names in copy_target or link_target, symlinked parent directories in save_target, or symlinked metadata filenames in SignedRole::write are not properly contained, allowing for unauthorized file writes.
Users are advised to upgrade to Tough version 0.22.0 or later and Tuftool version 0.15.0 or later. Additionally, review and update any forked or derivative code to incorporate the security fixes.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://aws.amazon.com/security/security-bulletins/2026-019-aws/ | AMZN | Vendor Advisory |
| https://crates.io/crates/tough/0.22.0 | AMZN | Product |
| https://crates.io/crates/tuftool/0.15.0 | AMZN | Product |
| https://github.com/awslabs/tough/releases/tag/tough-v0.22.0 | AMZN | Release Notes |
| https://github.com/awslabs/tough/releases/tag/tuftool-v0.15.0 | AMZN | Release Notes |
| https://github.com/awslabs/tough/security/advisories/GHSA-v57p-gppj-p9vg | AMZN | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | AMZN |
Affected Products
| Product | Versions |
|---|---|
| amazon tough | >= 0.9.0, < 0.22.0 |
CPE
Remediation
| |
| amazon tuftool | < 0.15.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | AMZN |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 6, 2026 | Initial Analysis | [email protected] |
| Apr 24, 2026 | CVE Modified | AMZN |
| Apr 24, 2026 | New CVE Received | AMZN |