PT-2026-5031 · Vlt · Vlt

Published

2026-01-27

·

Updated

2026-01-28

·

CVE-2026-24909

CVSS v3.1

5.9

Medium

VectorAV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions vlt versions prior to 1.0.0-rc.10
Description The software does not properly sanitize paths when extracting tar archives, which can allow for path traversal. This means a malicious tar archive could be crafted to write files outside of the intended destination directory.
Recommendations Update to version 1.0.0-rc.10 or later.

Fix

Relative Path Traversal

Weakness Enumeration

Related Identifiers

CVE-2026-24909
GHSA-GF2C-JWCJ-X929

Affected Products

Vlt