CVE-2020-7666: U-Root

High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.

This affects all versions of package github.com/u-root/u-root/pkg/cpio. It is vulnerable to leading, non-leading relative path traversal attacks and symlink based (relative and absolute) path traversal attacks in cpio file extraction.

Affected products

Published 2020-09-01. Last modified 2026-06-17.