CVE-2026-12565

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
17/06/2026
Last modified:
22/06/2026

Description

The unarchive internal module's archive extraction commands perform no code-level validation on extracted file paths, relying entirely on the behavior of external tools (e.g. GNU tar) which varies by platform. While CVE-2025-10284 addressed git-specific RCE vectors, the underlying archive extraction path traversal was never fixed. On systems with GNU tar

References to Advisories, Solutions, and Tools