Research / Finding
apko dirFS has a symlink-following path traversal that allows multiple entry points to escape the build root F-APKO-SYMLINK-001
Public snapshot: 26 Sep 2026. Status, releases and attribution belong to each source below; none is inferred from another record.
Read the evidence · View in research browse
Recorded evidence
7.5high
apko dirFS has a symlink-following path traversal that allows multiple entry points to escape the build root
Fixed in: apko v1.2.5
patched
details
Finding IDs F-APKO-SYMLINK-001 CVE CVE-2026-42574 GHSA GHSA-qq3r-w4hj-gjp6 Status patched Fixed in apko v1.2.5 Recorded credit reporter: @1seal Note symlink-following path traversal in apko dirFS allows multiple entry points to escape the build root CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVE registry state PUBLISHED CVE state checked 23 Sep 2026 F-APKO-SYMLINK-001: File / path escapes. Symlink traversal defeats filesystem containment. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-APKO-SYMLINK-001
Security area (1seal assessment): Authorization. Symlink traversal defeats filesystem containment. Reviewed 24 Sep 2026.
Clarify or correct this record privately . The email subject includes the finding ID. For an existing case, continue the agreed private thread. Do not post unpublished vulnerability details in public issues. Research disclosure policy .
How this page groups evidence This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules .