Back to database
Schedule35Medium6.4VulnerabilityCVE-2026-107174No patch link observed

CVE-2026-107174 — A flaw was found in source-to-image.

Published Oct 7, 2026, 03:17 PM UTCIngested 1d agoSource NVD(cve-db)CVE-2026-107174

Description

A flaw was found in source-to-image. When unpacking archive files, the application fails to properly sanitize symbolic links pointing to absolute file paths. An attacker who supplies a malicious builder image can exploit this vulnerability by embedding links pointing outside the extraction directory. This allows the attacker to bypass sandbox boundaries, potentially leading to unauthorized information disclosure or file modification on the host system.

CVSS v3.1 base metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
6.4

Medium severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Network

Attack Vector

AC

Low

Attack Complexity

PR

Low

Privileges Required

UI

None

User Interaction

S

Changed

Scope

C

Low

Confidentiality

I

Low

Integrity

A

None

Availability