VendorsLF Projectszarfall versions
Vulnerabilities

LF Projects Zarf

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2026-29064
Zarf: Symlink targets in archives are not validated against destination directory
Published 2026-03-06 · Analyzed
8.2EPSS 0.002
CVE-2026-40090
Zarf has a Path Traversal via Malicious Package Metadata.Name — Arbitrary File Write
Published 2026-04-14 · Analyzed
7.1EPSS 0.004