OVERVIEW CVE-2026-40090 is an arbitrary file write vulnerability affecting Zarf, an Airgap Native Packager Manager for Kubernetes, in versions 0.23.0 through 0.74.1. The vulnerability exists in the zarf package inspect sbom and zarf package inspect documentation subcommands, where attacker-controlled output directory paths can be exploited through crafted package metadata to write malicious files to arbitrary filesystem locations. SEVERITY The vulnerability carries a CVSS score of 7.1 (HIGH) with a network-based attack vector requiring minimal user interaction. An attacker can exploit this by modifying the Metadata.Name field in an unarchived package to include path traversal sequences (such as ../../etc/cron.d/malicious) or absolute paths targeting sensitive locations like SSH authorization keys. The attack allows writing arbitrary content to any filesystem location accessible by the user executing the inspect command, potentially enabling privilege escalation, unauthorized access, or system compromise. Attack complexity is low, though user interaction is required. EXPLOITATION STATUS This vulnerability is not currently listed on the Known Exploited Vulnerabilities catalog and shows no evidence of active exploitation in the wild. The EPSS score of 0.00046 indicates minimal probability of exploitation relative to the broader vulnerability landscape. The vulnerability has been patched in version 0.74.2, and organizations should prioritize upgrading to mitigate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.23.0, < 0.74.2CPE matchmatch criteria | cpe:2.3:a:lfprojects:zarf:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.