U Root is a Go-based toolkit for building custom Linux boot and runtime environments, addressing a specialized niche in embedded systems and bare-metal provisioning where conventional distributions are not suitable. The observed vulnerability surface remains confined to the toolkit itself with no clearly recurrent weakness class pattern established; current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by U Root over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7665HIGH This affects all versions of package github.com/u-root/u-root/pkg/uzip. It is vulnerable to both leading and non-leading relative path traversal attacks in zip file extraction. | Sep 1, 2020 | 7.5 | 23 | NO | NO |
CVE-2020-7669HIGH This affects all versions of package github.com/u-root/u-root/pkg/tarutil. It is vulnerable to both leading and non-leading relative path traversal attacks in tar file extraction. | Sep 1, 2020 | 7.5 | 20 | NO | NO |
CVE-2020-7666HIGH This affects all versions of package github.com/u-root/u-root/pkg/cpio. It is vulnerable to leading, non-leading relative path traversal attacks and symlink based (relative and abs | Sep 1, 2020 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by U Root.
Media articles that mention a CVE ID that affects a product developed by U Root — matched by CVE ID, not by vendor name.