CVE-2026-6968
EUVD-2026-2562924.04.2026, 20:16
Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated signing authority to write files outside intended output directories via absolute target names in copy_target/link_target, symlinked parent directories in save_target, or symlinked metadata filenames in SignedRole::write, because write paths trust the joined destination path without post-resolution containment verification. We recommend you upgrade to tough-v0.22.0 / tuftool-v0.15.0.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| amazon | tough | 0.9.0 ≤ 𝑥 < 0.22.0 |
| amazon | tuftool | 𝑥 < 0.15.0 |
𝑥
= Vulnerable software versions
References