PT-2026-37052 · Apko+1 · Apko+1

1Seal

+1

·

Published

2026-05-04

·

Updated

2026-05-10

·

CVE-2026-42574

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions apko versions 0.14.8 through 1.2.4
Description A crafted .apk file can install a TypeSymlink tar entry with a target pointing outside the build root. Subsequent directory-creation or file-write entries in the same or later archive can traverse this symlink to access host paths that the build user has permission to write to. The issue stems from the sanitizePath helper in pkg/apk/fs/rwosfs.go, which only rejected lexical .. traversal and failed to resolve or refuse symlinks. This affects disk-backed DirFS methods that pass caller-supplied paths to symlink-following standard library calls, including ReadFile(), WriteFile(), Chmod(), Chown(), Chtimes(), MkdirAll(), Mkdir(), and Mknod(). The primary reachable primitive during tar extraction is the MkdirAll() / Mkdir() / WriteFile() chain via apko build-cpio and disk-backed consumers like melange.
Recommendations Update to version 1.2.5.

Fix

Link Following

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-42574
GHSA-QQ3R-W4HJ-GJP6

Affected Products

Apko
Melange