Path traversal in tough - CVE-2026-6968
Published: April 25, 2026
tough
Detailed vulnerability description
The vulnerability allows a remote user to write files outside intended output directories.
The vulnerability exists due to path traversal in copy_target, link_target, save_target, and SignedRole::write when processing repository-controlled target names, parent directories, and metadata filenames. A remote user can supply crafted repository metadata and target paths to write files outside intended output directories.
Exploitation requires delegated signing authority in the remote repository.