CVE-2026-107174 — A flaw was found in source-to-image.
Description
A flaw was found in source-to-image. When unpacking archive files, the application fails to properly sanitize symbolic links pointing to absolute file paths. An attacker who supplies a malicious builder image can exploit this vulnerability by embedding links pointing outside the extraction directory. This allows the attacker to bypass sandbox boundaries, potentially leading to unauthorized information disclosure or file modification on the host system.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:NMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
PR
Low
Privileges Required
UI
None
User Interaction
S
Changed
Scope
C
Low
Confidentiality
I
Low
Integrity
A
None
Availability
References
Related threats
same CWE or vendorCVE-2026-106566 — ImageMagick is free and open-source software used for editing and manipulating digital images.
CVE-2026-106566 · 1d ago
CVE-2026-103435 — Claude Code validated that a target file path resided within the project working directory at permission-check time, but re-resolved the path at wr…
CVE-2026-103435 · 1d ago
CVE-2026-106507 — Backstage is an open framework for building developer portals.
CVE-2026-106507 · 2d ago
CVE-2026-105712 — gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive.
CVE-2026-105712 · 3d ago
Dulwich: Symlink write-through in checkout(paths=[]) via raw os.open bypasses all symlink protections
OSV · 6d ago
CVE-2026-97024 — A path traversal vulnerability in Flatpak's handling of the files/etc directory during app deployment allows a malicious Flatpak app to cause certa…
CVE-2026-97024 · 10d ago