CVE-2026-105712
Received Received - Intake

Symlink File Overwrite in GnuPG gpgtar

Vulnerability report for CVE-2026-105712, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: MITRE

Description

gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
GnuPG GnuPG 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-61 The product, when opening a file or directory, does not sufficiently account for when the file is a symbolic link that resolves to a target outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in gpgtar (part of GnuPG) allows file overwrite when extracting archives with the --directory (-C) option. If the target directory contains a pre-existing symlink, gpgtar may follow it and write files outside the intended directory. This is limited by the user's filesystem permissions. Extracting into an empty directory avoids this risk.

Detection Guidance

To detect this vulnerability, check if your system is running a vulnerable version of GnuPG (before 2.5.19). Run 'gpg --version' to see the installed version. If the version is below 2.5.19, the system is vulnerable. Additionally, inspect any scripts or tools using gpgtar with the --directory option for potential symlink risks.

Impact Analysis

An attacker could craft an archive that overwrites sensitive files on your system if you use gpgtar with --directory in a directory containing symlinks. This could lead to data corruption, unauthorized file modifications, or potential privilege escalation depending on the files affected.

Compliance Impact

This vulnerability could lead to unauthorized file access or modification, potentially violating data integrity and confidentiality requirements in GDPR and HIPAA. Organizations must ensure proper file handling to maintain compliance with these regulations.

Mitigation Strategies

Upgrade GnuPG to version 2.5.19 or later immediately. This version includes fixes for the gpgtar vulnerability. After upgrading, avoid using the --directory option with gpgtar on untrusted archives or ensure the target directory is empty and not a symlink.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105712. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart