PT-2026-21924 · Google · Flutter Sdk+1

Splitline

·

Published

2026-02-25

·

Updated

2026-03-13

·

CVE-2026-27704

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dart SDK versions prior to 3.11.0 Flutter SDK versions prior to 3.41.0
Description The Dart and Flutter SDKs are susceptible to a path traversal issue within the pub client (dart pub and flutter pub) when extracting package archives from the PUB CACHE. A malicious package archive could potentially write files outside the intended destination directory. This occurs because the pub client does not properly normalize file paths before writing files, allowing an attacker to traverse up the directory structure using symlinks. The issue is addressed by normalizing the file path before writing, preventing unauthorized file access. All packages on pub.dev have been vetted for this issue, and new packages are no longer permitted to contain symlinks.
Recommendations Dart SDK versions prior to 3.11.0 should be updated to version 3.11.0 or later. Flutter SDK versions prior to 3.41.0 should be updated to version 3.41.0 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27704
GHSA-Q739-79RH-VMVP

Affected Products

Dart Sdk
Flutter Sdk