PT-2026-35081 · Awslabs · Tough

1Seal

·

Published

2026-04-24

·

Updated

2026-05-21

·

CVE-2026-6968

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions awslabs/tough versions prior to 0.22.0
Description Incomplete path traversal fixes allow remote authenticated users with delegated signing authority to write files outside intended output directories. This occurs because write paths trust the joined destination path without post-resolution containment verification. The issue can be triggered via absolute target names in 'copy target/link target', symlinked parent directories in 'save target', or symlinked metadata filenames in the SignedRole::write function.
Recommendations Upgrade to version 0.22.0.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6968

Affected Products

Tough