The ArchiveReader.extractContents() function used by cctl image load and container image load performs no pathname validation before extracting an archive member. This means that a carelessly or maliciously constructed archive can extract a file into any user-writable location on the system using relative pathnames. This issue is addressed in container 0.8.0 and containerization 0.21.0.
References
| Link | Resource |
|---|---|
| https://github.com/apple/containerization/security/advisories/GHSA-cq3j-qj2h-6rv3 | Exploit Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-01-23 00:15
Updated : 2026-01-27 20:17
NVD link : CVE-2026-20613
Mitre link : CVE-2026-20613
CVE.ORG link : CVE-2026-20613
JSON object : View
Products Affected
apple
- containerization
- container
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
