CVE-2026-29790 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

dbt-common is the shared common utilities for dbt-core and adapter implementations use. Prior to versions 1.34.2 and 1.37.3, a path traversal vulnerability exis…
Low CVSS: 2.0

CVE-2026-29790

dbt-common is the shared common utilities for dbt-core and adapter implementations use. Prior to versions 1.34.2 and 1.37.3, a path traversal vulnerability exists in dbt-common's safe_extract() function used when extracting tarball archives. The function uses os.path.commonprefix() to validate that extracted files remain within the intended destination directory. However, commonprefix() compares paths character-by-character rather than by path components, allowing a malicious tarball to write files to sibling directories with matching name prefixes. This issue has been patched in versions 1.34.2 and 1.37.3.
Vendor
Getdbt
Product
Dbt-common
CWE
CWE-22
Yayın Tarihi
2026-03-06 21:16:15
Güncelleme
2026-03-13 18:31:00
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar