{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/unearth--0.18.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-73030"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["unearth (\u003c= 0.18.2)"],"_cs_severities":["high"],"_cs_tags":["path-traversal","vulnerability","supply-chain"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe unearth library, used for utility operations in Python environments, contains a critical path traversal vulnerability (CVE-2026-73030) in its \u003ccode\u003eis_within_directory\u003c/code\u003e function. The vulnerability stems from the library's failure to normalize file paths before performing directory containment validation. By exploiting this flaw, an attacker can supply specially crafted tar archives containing directory traversal sequences (e.g., \u003ccode\u003e../\u003c/code\u003e) or malicious symlinks to break out of the target extraction directory. Successful exploitation allows the attacker to write files to arbitrary locations on the filesystem, restricted only by the permissions of the process executing the unearth library. This vulnerability impacts all versions up to 0.18.2. Users are advised to update to a patched version, as the fix was implemented in commit 6c78164. Given the nature of libraries like unearth, this could affect a wide range of downstream applications that process external archives.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability carries a CVSS v3.1 base score of 8.1, indicating a high impact on system integrity and security. If exploited, an attacker could achieve arbitrary file write, potentially leading to remote code execution by overwriting critical system binaries, configuration files, or startup scripts, depending on the context in which the library is utilized within an application.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all instances of the unearth library within the environment and inventory applications that utilize version 0.18.2 or earlier.\u003c/li\u003e\n\u003cli\u003eUpgrade the unearth dependency to a version containing the fix for CVE-2026-73030 (as implemented in commit 6c78164).\u003c/li\u003e\n\u003cli\u003eImplement file integrity monitoring (FIM) on directories where third-party archives are extracted to detect anomalous file creation patterns.\u003c/li\u003e\n\u003cli\u003eRun processes that utilize unearth with the principle of least privilege, ensuring the service user has minimal write access to the filesystem.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-10T21:40:43Z","date_published":"2026-08-10T21:40:43Z","id":"https://feed.craftedsignal.io/briefs/2026-08-unearth-path-traversal/","summary":"The unearth library version 0.18.2 and earlier contains a path traversal vulnerability in the is_within_directory function that permits arbitrary file writes via malicious archives.","title":"Path Traversal Vulnerability in unearth Library","url":"https://feed.craftedsignal.io/briefs/2026-08-unearth-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Unearth (\u003c= 0.18.2)","version":"https://jsonfeed.org/version/1.1"}