CVE-2026-5704
A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.
- Published Apr 6, 2026
- CVSS 5.5 medium
- 0.4% chance of exploitation in the next 30 days (EPSS)
- Public exploit code is available
- A fix is available