{"id":"CVE-2026-105712","title":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive","summary":"gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that sy…","severity":"low","cvss":3.6,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L","cwe":["CWE-61"],"vendor":"GnuPG","product":"GnuPG","affected":["GnuPG < 2.5.19"],"published":"2026-10-05","updated":"2026-10-05","sourceUpdated":"2026-10-05T20:17:20.460","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105712","references":[{"url":"https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88","label":"cve@mitre.org"},{"url":"https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html","label":"cve@mitre.org"},{"url":"https://static.dev.gnupg.org/T8159.html","label":"cve@mitre.org"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-05T19:09:21.224782Z"},"ingestedAt":"2026-10-05T19:30:59.981Z","slug":"CVE-2026-105712","body":"## Overview\n\ngpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":20,"depthScoreParts":{"impact":19.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}