apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before version 1.2.5, a crafted .apk could install a TypeSymlink tar entry whose target pointed outside the build root, and a subsequent directory-creation or file-write entry in the same or later archive could traverse that symlink to reach host paths the build user could write to. This issue has been patched in version 1.2.5.
Metrics
Affected Vendors & Products
References
History
Sat, 09 May 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chainguard-dev
Chainguard-dev apko |
|
| Vendors & Products |
Chainguard-dev
Chainguard-dev apko |
Sat, 09 May 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before version 1.2.5, a crafted .apk could install a TypeSymlink tar entry whose target pointed outside the build root, and a subsequent directory-creation or file-write entry in the same or later archive could traverse that symlink to reach host paths the build user could write to. This issue has been patched in version 1.2.5. | |
| Title | apko dirFS has a symlink-following path traversal that allows multiple entry points to escape the build root | |
| Weaknesses | CWE-22 CWE-59 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-09T19:24:48.497Z
Reserved: 2026-04-28T17:26:12.085Z
Link: CVE-2026-42574
No data.
Status : Received
Published: 2026-05-09T20:16:29.420
Modified: 2026-05-09T20:16:29.420
Link: CVE-2026-42574
No data.
OpenCVE Enrichment
Updated: 2026-05-09T21:00:12Z