CVE-2026-24909
Severity CVSS v4.0:
Pending analysis
Type:
CWE-23
Relative Path Traversal
Publication date:
27/01/2026
Last modified:
27/01/2026
Description
vlt before 1.0.0-rc.10 mishandles path sanitization for tar, leading to path traversal during extraction.
Impact
Base Score 3.x
5.90
Severity 3.x
MEDIUM



