CVE 8.2 HIGH

melange QEMU runner could write files outside workspace directory_CVE-2026-24843

8.2 / 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:H

Description

melange allows users to build apk packages using declarative pipelines. In version 0.11.3 to before 0.40.3, an attacker who can influence the tar stream from a QEMU guest VM could write files outside the intended workspace directory on the host. The retrieveWorkspace function extracts tar entries without validating that paths stay within the workspace, allowing path traversal via ../ sequences. This issue has been patched in version 0.40.3.

Basic Information

ID CVE-2026-24843
Source GitHub_M
Published Feb 4, 2026 at 19:31

Affected Product

Vendor chainguard-dev
Product melange
Version >= 0.11.3, < 0.40.3
Affected Versions chainguard-dev melange >= 0.11.3, < 0.40.3

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.