CVE-2026-49248 - OneDev: RCE through absolute-path symlink following allows low-privileged users to overwrite arbitrary server via TarUtils.untar
CVE ID :CVE-2026-49248 Published : June 18, 2026, 7:54 p.m. | 5 hours, 15 minutes ago Description :OneDev is a Git server with CI/CD, kanban, and packages. In versions 15.0.6 and below, TarUtils.untar() creates symbolic links verbatim from TAR entry getLinkName() without validating whether...