
BOSH CLI の blobs.yml にパス走査。リリースを展開しただけで作業ディレクトリの外に書き込まれます。CVSS 9.1、修正版は v7.10.4。危ないのは開発者の端末より、人が見ていないCIのランナーのほうです。まずどこで自動実行されているかを洗い出してください。 https://cve.autoarticles.net/cve/CVE-2026-47826
Post summary
The post alerts about CVE‑2026‑47826, a path‑traversal flaw in BOSH CLI with a CVSS score of 9.1, and notes that patch version v7.10.4 is available. It urges users to identify where automatic execution may occur, emphasizing the need to apply the fix.

