CVE-2026-29064: Zarf's symlink targets in archives are not validated against destination directory
A path traversal vulnerability in archive extraction allows a specifically crafted Zarf package to create symlinks pointing outside the destination directory, enabling arbitrary file read or write on the system processing the package.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-29064 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →