PT-2026-6211 · Melange · Melange

1Seal

·

Published

2026-02-03

·

Updated

2026-02-06

·

CVE-2026-24843

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions melange versions 0.11.3 through 0.40.2
Description melange is a tool that allows users to build apk packages using declarative pipelines. A security issue exists where an attacker who can influence the tar stream from a QEMU guest VM could write files outside the intended workspace directory on the host system. The retrieveWorkspace function extracts tar entries without validating that paths remain within the workspace, enabling path traversal through the use of '../' sequences.
Recommendations Update to version 0.40.3 or later.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-24843
GHSA-QXX2-7H4C-83F4
GO-2026-4407
SUSE-SU-2026:0403-1

Affected Products

Melange