Sceawere
Vulnerability Detail
CVE-2026-105712UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
gpgtar Arbitrary File Overwrite Vulnerability
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.6
- Creation Date
- 1d ago
- Vendor
- GnuPG
- Product
- GnuPG
- Attack Type
- CWE-61 UNIX Symbolic Link (Symlink) Following
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L
- Attack Complexity
- HIGH
Narrative and Response
Description
gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.6",
"pubDate": "2026-10-05T19:17:19.527Z",
"pubdate": "2026-10-05T19:17:19.527Z",
"executiveSummary": "gpgtar in GnuPG versions prior to 2.5.19 is susceptible to an arbitrary file overwrite vulnerability stemming from insecure symlink handling during archive extraction.\nThis vulnerability is categorized as a path traversal or symlink following issue. An attacker can craft a malicious archive containing symbolic links that, when extracted using the --directory (-C) flag, causes the application to write files outside of the designated target directory.\nThe scope of the impact is strictly governed by the filesystem permissions of the user executing the extraction process. While the vulnerability requires the presence of a pre-existing symlink within the target directory, it provides an attacker the ability to overwrite arbitrary files accessible to the current user.\nThe risk is primarily relevant when extracting untrusted archives into directories that are not empty or properly sanitized. No authentication is required to exploit this flaw, as the attack vector relies solely on the processing of malicious archive structures. Systems that exclusively extract archives into fresh, isolated, or empty directories are currently not at risk from this specific exploit path.",
"technicalDetails": "The vulnerability resides in the archive extraction logic of gpgtar, specifically in how the utility resolves file paths when the --directory (-C) flag is utilized. The component fails to sufficiently validate or constrain the destination of extracted files if the extraction path contains a symbolic link targeting a location outside of the intended extraction root.\nThe root cause is a lack of path sanitization or 'jail' enforcement that fails to account for symlinks that exist on the filesystem prior to the extraction operation. When gpgtar processes an archive entry that contains a file path, it attempts to resolve the destination path relative to the provided directory argument.\nIn a typical attack flow: 1) The attacker creates a malicious archive containing a symlink or a file that is designed to traverse the filesystem structure. 2) The victim identifies a target directory that contains a pre-existing symbolic link (potentially placed there by a prior, unrelated action or a secondary attack vector). 3) The victim invokes gpgtar with the --directory flag pointed at the directory containing the link. 4) As gpgtar iterates through the archive, it follows the attacker-controlled symlink during the file creation process, effectively escaping the intended directory boundary.\nThe payload behavior involves the extraction of a file that writes to an unintended location, such as overwriting configuration files, binaries, or sensitive data, depending on the privileges of the user running the gpgtar process. Because the application blindly follows the symlink, it treats the resolved path as a valid destination within the extraction target.\nThe vulnerability affects all versions of GnuPG prior to 2.5.19. The exploitation does not require network exposure, as it is a local filesystem operation. Privilege requirements are limited to the permissions assigned to the user account executing the extraction. If the user running gpgtar has write access to system-wide directories or sensitive user-specific files, those files are susceptible to modification or corruption. There is no requirement for pre-existing authentication to the GnuPG utility itself, as the exploit is triggered solely by the act of processing a crafted, untrusted input file."
}