tar archive path traversal in build context extraction allows writing files outside destination directory
Upstream fixed versions: package name not specified: no patched version listed
details
- Finding IDs
- F-CHAINGUARD-FORKS-KANIKO-AG5-001
- CVE
- CVE-2026-28406
- GHSA
- GHSA-6rxq-q92g-4rmf
- Status
- unpatched
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
- CVE registry state
- PUBLISHED
- CVE state checked
- Upstream title
- tar archive path traversal in build context extraction allows writing files outside destination directory
- Upstream CWE
- CWE-22
- Upstream publication
- Upstream updated
- Metadata fetched
- Upstream fixed versions
- package name not specified: no patched version listed
- Upstream affected ranges
- package name not specified: >= 1.25.4, <= 1.25.7
- Upstream @1seal credit
- @1seal: reporter (accepted)
F-CHAINGUARD-FORKS-KANIKO-AG5-001: File / path escapes. Archive extraction crosses the intended build filesystem boundary. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-CHAINGUARD-FORKS-KANIKO-AG5-001
Security area (1seal assessment): Authorization. Build-context archive paths can escape the extraction directory; the primary defect is missing path containment. Reviewed 21 Sep 2026.