{"id":"GO-2026-5542","summary":"Path traversal via malicious package name in github.com/zarf-dev/zarf","details":"A path traversal vulnerability in Zarf allows an attacker to write arbitrary files on the host system by providing a malicious package name in the package metadata. This occurs when Zarf generates SBOM or documentation outputs, or when creating a package, as it fails to properly sanitize the package name before using it in a file path.","aliases":["CVE-2026-40090","GHSA-pj97-4p9w-gx3q"],"modified":"2026-07-23T17:00:24.617246673Z","published":"2026-07-23T16:32:52Z","database_specific":{"url":"https://pkg.go.dev/vuln/GO-2026-5542","review_status":"REVIEWED"},"references":[{"type":"ADVISORY","url":"https://github.com/zarf-dev/zarf/security/advisories/GHSA-pj97-4p9w-gx3q"},{"type":"FIX","url":"https://github.com/zarf-dev/zarf/pull/4793"}],"affected":[{"package":{"name":"github.com/defenseunicorns/zarf","ecosystem":"Go","purl":"pkg:golang/github.com/defenseunicorns/zarf"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.23.0"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/defenseunicorns/zarf/src/pkg/packager","symbols":["Packager.Create"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-5542.json"}},{"package":{"name":"github.com/zarf-dev/zarf","ecosystem":"Go","purl":"pkg:golang/github.com/zarf-dev/zarf"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.37.0"},{"fixed":"0.74.2"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/zarf-dev/zarf/src/pkg/packager","symbols":["Create","GetPackageFromSourceOrCluster","LoadPackage","Pull"]},{"path":"github.com/zarf-dev/zarf/src/pkg/packager/layout","symbols":["PackageLayout.Archive","PackageLayout.FileName"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-5542.json"}}],"schema_version":"1.7.5"}