Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4x2g-7mfh-8rx6

Опубликовано: 15 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.4

Описание

On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host code execution.

On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host code execution.

EPSS

Процентиль: 6%
0.0016
Низкий

9.4 Critical

CVSS4

Дефекты

CWE-59

Связанные уязвимости

nvd
9 дней назад

On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as the VMM user, potentially achieving host code execution.

EPSS

Процентиль: 6%
0.0016
Низкий

9.4 Critical

CVSS4

Дефекты

CWE-59