Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qxx2-7h4c-83f4

Опубликовано: 03 фев. 2026
Источник: github
Github: Прошло ревью
CVSS3: 8.2

Описание

melange QEMU runner could write files outside workspace directory

An attacker who can influence the tar stream from a QEMU guest VM could write files outside the intended workspace directory on the host. The retrieveWorkspace function extracts tar entries without validating that paths stay within the workspace, allowing Path Traversal via ../ sequences.

Fix: Fixed in 6e243d0d. Merged in release.

Acknowledgements

melange thanks Oleh Konko from 1seal for discovering and reporting this issue.

Пакеты

Наименование

chainguard.dev/melange

go
Затронутые версииВерсия исправления

>= 0.11.3, < 0.40.3

0.40.3

EPSS

Процентиль: 3%
0.00017
Низкий

8.2 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.2
nvd
3 дня назад

melange allows users to build apk packages using declarative pipelines. In version 0.11.3 to before 0.40.3, an attacker who can influence the tar stream from a QEMU guest VM could write files outside the intended workspace directory on the host. The retrieveWorkspace function extracts tar entries without validating that paths stay within the workspace, allowing path traversal via ../ sequences. This issue has been patched in version 0.40.3.

EPSS

Процентиль: 3%
0.00017
Низкий

8.2 High

CVSS3

Дефекты

CWE-22