Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-qq3r-w4hj-gjp6 | apko dirFS has a symlink-following path traversal that allows multiple entry points to escape the build root |
Mon, 11 May 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 09 May 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chainguard-dev
Chainguard-dev apko |
|
| Vendors & Products |
Chainguard-dev
Chainguard-dev apko |
Sat, 09 May 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before version 1.2.5, a crafted .apk could install a TypeSymlink tar entry whose target pointed outside the build root, and a subsequent directory-creation or file-write entry in the same or later archive could traverse that symlink to reach host paths the build user could write to. This issue has been patched in version 1.2.5. | |
| Title | apko dirFS has a symlink-following path traversal that allows multiple entry points to escape the build root | |
| Weaknesses | CWE-22 CWE-59 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-11T17:11:40.244Z
Reserved: 2026-04-28T17:26:12.085Z
Link: CVE-2026-42574
Updated: 2026-05-11T17:11:17.756Z
Status : Deferred
Published: 2026-05-09T20:16:29.420
Modified: 2026-05-13T15:23:57.230
Link: CVE-2026-42574
No data.
OpenCVE Enrichment
Updated: 2026-05-09T21:00:12Z
Github GHSA