CVE-2026-6968Disclosure(amazon / tough)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated signing authority to write files outside intended output directories via absolute target names in copy_target/link_target, symlinked parent directories in save_target, or symlinked metadata filenames in SignedRole::write, because write paths trust the joined destination path without post-resolution containment verification. We recommend you upgrade to tough-v0.22.0 / tuftool-v0.15.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tough
  • tuftool

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-05-21)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
toughtuftool

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-24: 1Mentions · 2026-04-25: 1Mentions · 2026-05-21: 2Technical Details · 2026-04-24: 1Technical Details · 2026-04-25: 1Technical Details · 2026-05-21: 104-2404-2505-21
Signal classification1 categories
Disclosure
4100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-241
Disclosure1
2026-04-251
Disclosure1
2026-05-212
Disclosure2
Full discourse4 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-6968: Path Traversal in Metadata Filenames (CVSS 5.7) CWE-22: Improper Pathname Restriction TL;DR AWS's awslabs/tough library—the Rust implementation of The Update Framework (TUF) standard—has three vulnerabilities that allow authenticated attackers to forge…

    Post summary

    AWS’s awslabs/tough Rust library includes a path traversal vulnerability (CVE‑2026‑6968) noted with CVSS 5.7; the post provides technical details but no PoC, exploit code, active exploitation, or patch.

    1000038
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The Foundation Cracked: AWS tough Library Breaks TUF Metadata Integrity (CVE-2026-6967, CVE-2026-6966, CVE-2026-6968). TL;DR AWS's awslabs/tough library—the Rust implementation of The Update Framework (TUF) standard—has three vulnerabilities that allow authenticated…

    Post summary

    The post announces three CVEs in AWS's awslabs/tough TUF library, outlining that three vulnerabilities exist but providing no further details such as PoC, exploit code, or patches.

    1000053
    227 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6968 Path Traversal in awslabs/tough Before Version 0.22.0 Allows Unaut... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6968 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet announces a path‑traversal vulnerability (CVE‑2026‑6968) in awslabs/tough before version 0.22.0, providing a link for more details but no evidence of exploitation, PoC, or patch information.

    0000039
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6968 Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated signing authority to write files outside intended … https://www.cve.org/CVERecord?id=CVE-2026-6968

    Post summary

    The post announces CVE-2026-6968, detailing a path traversal flaw in awslabs/tough before version 0.22.0 that permits authenticated users with delegated signing authority to write files outside intended directories. No exploit, PoC, or patch information is provided.

    0000056
    57.2K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appamazontough-rust-
Appamazontuftool-rust-

Explore more