github.com/zarf-dev/zarf
GHSA-pj97-4p9w-gx3q
Gomalware4/14/2026
Description
Zarf has a Path Traversal via Malicious Package Metadata.Name — Arbitrary File Write
Details
EcosystemGo
Attack Typemalware
Published4/14/2026
Affected Versions
0.23.0
Related CVEs
Aliases
CVE-2026-40090
Quick Actions