Path traversal in melange's external pipeline resolver (pipeline[].uses) allows loading a pipeline from outside the pipeline directories
Fixed in: melange v0.43.4
details
- Finding IDs
- F-MELANGE-008
- CVE
- CVE-2026-29050
- GHSA
- GHSA-98f2-w9h9-7fp9
- Status
- patched
- Fixed in
- melange v0.43.4
- Recorded credit
- reporter: @1seal
- Note
- GHSA-98f2-w9h9-7fp9 · external pipeline resolver path traversal
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
- CVE registry state
- PUBLISHED
- CVE state checked
- Upstream title
- Path traversal in melange's external pipeline resolver (pipeline[].uses) allows loading a pipeline from outside the pipeline directories
- Upstream CWE
- CWE-22
- Upstream publication
- Upstream updated
- Metadata fetched
- Upstream @1seal credit
- @1seal: reporter (accepted)
F-MELANGE-008: File / path escapes. External pipeline resolution escapes the intended directory. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-MELANGE-008
Security area (1seal assessment): Authorization. External pipeline resolution escapes the intended directory. Reviewed 24 Sep 2026.