apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before version 1.2.5, a crafted .apk could install a TypeSymlink tar entry whose target pointed outside the build root, and a subsequent directory-creation or file-write entry in the same or later archive could traverse that symlink to reach host paths the build user could write to. This issue has been patched in version 1.2.5.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-qq3r-w4hj-gjp6 | apko dirFS has a symlink-following path traversal that allows multiple entry points to escape the build root |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 09 May 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chainguard-dev
Chainguard-dev apko |
|
| Vendors & Products |
Chainguard-dev
Chainguard-dev apko |
Sat, 09 May 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before version 1.2.5, a crafted .apk could install a TypeSymlink tar entry whose target pointed outside the build root, and a subsequent directory-creation or file-write entry in the same or later archive could traverse that symlink to reach host paths the build user could write to. This issue has been patched in version 1.2.5. | |
| Title | apko dirFS has a symlink-following path traversal that allows multiple entry points to escape the build root | |
| Weaknesses | CWE-22 CWE-59 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-09T19:24:48.497Z
Reserved: 2026-04-28T17:26:12.085Z
Link: CVE-2026-42574
No data.
Status : Received
Published: 2026-05-09T20:16:29.420
Modified: 2026-05-09T20:16:29.420
Link: CVE-2026-42574
No data.
OpenCVE Enrichment
Updated: 2026-05-09T21:00:12Z
Github GHSA