CVE-2026-27704Disclosure(dart / dart_software_development_kit)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Dart and Flutter SDKs provide software development kits for the Dart programming language. In versions of the Dart SDK prior to 3.11.0 and the Flutter SDK prior to version 3.41.0, when the pub client (`dart pub` and `flutter pub`) extracts a package in the pub cache, a malicious package archive can have files extracted outside the destination directory in the `PUB_CACHE`. A fix has been landed in commit 26c6985c742593d081f8b58450f463a584a4203a. By normalizing the file path before writing file, the attacker can no longer traverse up via a symlink. This patch is released in Dart 3.11.0 and Flutter 3.41.0.vAll packages on pub.dev have been vetted for this vulnerability. New packages are no longer allowed to contain symlinks. The pub client itself doesn't upload symlinks, but duplicates the linked entry, and has been doing this for years. Those whose dependencies are all from pub.dev, third-party repositories trusted to not contain malicious code, or git dependencies are not affected by this vulnerability.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dart_software_development_kit
  • flutter

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-25); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
dart_software_development_kitflutter

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-25: 1Mentions · 2026-02-28: 1Technical Details · 2026-02-25: 102-2502-28
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-251
Disclosure1
2026-02-281
General1
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27704 Path Traversal Vulnerability in Dart and Flutter SDKs Pub Client Before 3.11.0 and 3.41.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27704

    Post summary

    A path traversal vulnerability (CVE-2026-27704) exists in Dart and Flutter SDKs Pub Client versions prior to 3.11.0 and 3.41.0.

    0000148
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-27704 The Dart and Flutter SDKs provide software development kits for the Dart programming language. In versions of the Dart SDK prior to 3.11.0 and the Flutter SDK prior t… https://www.cve.org/CVERecord?id=CVE-2026-27704

    Post summary

    The text references CVE-2026-27704 and links to its CVE record, but provides no further details about the vulnerability, exploitation, or mitigation.

    00000200
    56.6K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appdartdart_software_development_kit---
Appflutterflutter---

Explore more