Microsoft Security Response CenterCVE-2026-105712
gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink, gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory. The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh empty directory does not have this risk.
LowVendor CVSS 3.6 / 10 1 CVE
Published Oct 7, 2026 at 1:02 AM UTC