Vulnerability Description
apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1, a path traversal vulnerability was discovered in apko's dirFS filesystem abstraction. An attacker who can supply a malicious APK package (e.g., via a compromised or typosquatted repository) could create directories or symlinks outside the intended installation root. The MkdirAll, Mkdir, and Symlink methods in pkg/apk/fs/rwosfs.go use filepath.Join() without validating that the resulting path stays within the base directory. This issue has been patched in version 1.1.1.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Chainguard | Apko | >= 0.14.8, < 1.1.1 |
Related Weaknesses (CWE)
References
- https://github.com/chainguard-dev/apko/commit/d8b7887a968a527791b3c591ae83928cb4Patch
- https://github.com/chainguard-dev/apko/security/advisories/GHSA-5g94-c2wx-8pxwThird Party Advisory
FAQ
What is CVE-2026-25121?
CVE-2026-25121 is a vulnerability with a CVSS score of 7.5 (HIGH). apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1, a path traversal vulnerability was discovered in apko's dirFS filesystem abstr...
How severe is CVE-2026-25121?
CVE-2026-25121 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-25121?
Check the references section above for vendor advisories and patch information. Affected products include: Chainguard Apko.