Loading market data...
← Back to CVE feed

CVE-2026-79705

MEDIUM CVSS 4.5 View on NVD ↗

Description

A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archive containing malicious symlinks can escape the target extraction directory and create files outside the intended destination. Buildah itself uses chroot hardening and is not affected.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N
Published: Sep 15, 2026 17:17 UTC Modified: Sep 15, 2026 18:19 UTC