CVE-2026-29064 is a high-severity path traversal vulnerability (CVSS 8.2) affecting Zarf, an Airgap Native Packager Manager for Kubernetes, in versions 0.54.0 through 0.73.0. This flaw allows a specially crafted Zarf package to create symbolic links outside the intended directory, leading to arbitrary file read or write capabilities on the system processing the package. The attack requires user interaction (UI:R) to process the malicious package. There is no evidence of active exploitation, nor are there public exploits available in Metasploit, Nuclei, or ExploitDB. Community discussion is minimal, with only one mention identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.54.0, < 0.73.1CPE matchmatch criteria | cpe:2.3:a:lfprojects:zarf:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.