๐Ÿ” CVE Alert

CVE-2026-27704

UNKNOWN 0.0

Dart SDK and Flutter SDK have Zip slip in Dart Pub package extraction

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Dart and Flutter SDKs provide software development kits for the Dart programming language. In versions of the Dart SDK prior to 3.11.0 and the Flutter SDK prior to version 3.41.0, when the pub client (`dart pub` and `flutter pub`) extracts a package in the pub cache, a malicious package archive can have files extracted outside the destination directory in the `PUB_CACHE`. A fix has been landed in commit 26c6985c742593d081f8b58450f463a584a4203a. By normalizing the file path before writing file, the attacker can no longer traverse up via a symlink. This patch is released in Dart 3.11.0 and Flutter 3.41.0.vAll packages on pub.dev have been vetted for this vulnerability. New packages are no longer allowed to contain symlinks. The pub client itself doesn't upload symlinks, but duplicates the linked entry, and has been doing this for years. Those whose dependencies are all from pub.dev, third-party repositories trusted to not contain malicious code, or git dependencies are not affected by this vulnerability.

CWE CWE-22
Vendor dart-lang
Product sdk
Published Feb 25, 2026
Last Updated Feb 25, 2026
Stay Ahead of the Next One

Get instant alerts for dart-lang sdk

Be the first to know when new unknown vulnerabilities affecting dart-lang sdk are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

dart-lang / sdk
< 3.11.0
dart-lang / flutter
< 3.41.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/dart-lang/sdk/security/advisories/GHSA-q739-79rh-vmvp github.com: https://github.com/dart-lang/pub/commit/26c6985c742593d081f8b58450f463a584a4203a