
FeltSteam0@FeltSteam
@dr3dn0t @AndrewOrlowski But if you look at some of the CVE's like CVE-2026-65617 or CVE-2026-65921 they have credit type "finder" but their actual discovery-source field set to UNKNOWN
1000036
610 followersView on X
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside the intended build artifacts location.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE
If you run products in this scope, you should treat this CVE as relevant to your environment.

@dr3dn0t @AndrewOrlowski But if you look at some of the CVE's like CVE-2026-65617 or CVE-2026-65921 they have credit type "finder" but their actual discovery-source field set to UNKNOWN
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | jfrog | artifactory | - | - | - |