Directory Traversal Affecting zarf-fips package, versions <0.81.1-r0


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.35% (27th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CHAINGUARDLATEST-ZARFFIPS-18007883
  • published18 Jul 2026
  • disclosed17 Jul 2026

Introduced: 17 Jul 2026

NewCVE-2026-50163  (opens in a new tab)
CWE-22  (opens in a new tab)
CWE-59  (opens in a new tab)

How to fix?

Upgrade Chainguard zarf-fips to version 0.81.1-r0 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream zarf-fips package and not the zarf-fips package as distributed by Chainguard. See How to fix? for Chainguard relevant fixed versions and status.

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/utils.go:262-275 validates a hardlink target relative to the extract base but returns the unresolved target, causing os.Link("victim.secret", "<extract_base>/payload.tar.gz/evil_cwd_link") to resolve header.Linkname against the process current working directory for a Typeflag=TypeLink entry such as Name=payload.tar.gz/evil_cwd_link and Linkname="victim.secret" with io.deis.oras.content.unpack: "true", which can expose or tamper with files such as .env, .git/config, .aws/credentials, and ~/.ssh/config. This issue is fixed in version 2.6.2.

CVSS Base Scores

version 3.1