[High] CVE-2026-41011 – PackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join...
High CVE-2026-41011 PackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz") and name = package_meta['name'] comes directly from release.MF inside the uploaded tarball. The string is passed to Bosh::Common::Exec.sh, which executes via...