CVE-2026-24909: Vlt

Medium severity, CVSS 5.9. EPSS: 0.2% chance of exploitation in the next 30 days.

vlt before 1.0.0-rc.10 mishandles path sanitization for tar, leading to path traversal during extraction.

Affected products

  • Vlt Vlt: before 1.0.0-rc.10 (fixed in 1.0.0-rc.10)

Published 2026-01-27. Last modified 2026-06-17.