VDB

CVE-2026-50163

CVE-2026-50163 PUBLISHED CVSS 7.1 HIGH

Reported by GitHub_M · Published July 17, 2026

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/utils.go:262-275 validates a hardlink target relative to the extract base but returns the unresolved target, causing os.Link("victim.secret", "<extract_base>/payload.tar.gz/evil_cwd_link") to resolve header.Linkname against the process current working directory for a Typeflag=TypeLink entry such as Name=payload.tar.gz/evil_cwd_link and Linkname="victim.secret" with io.deis.oras.content.unpack: "true", which can expose or tamper with files such as .env, .git/config, .aws/credentials, and ~/.ssh/config. This issue is fixed in version 2.6.2.

Risk Scores

CVSS 3.1
7.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N

Affected Products

VendorProductVersions
oras-projectoras-go< 2.6.2
wolfiargocd-image-updater0, 0, 0
chainguardk8sgpt*, *, *
chainguardconsul-k8s-fips-1.7*, *, *
wolfiargo-cd-3.20, 0, 0
wolfihelm-push*, *, *
chainguardkargo-1.9*, *, *
chainguardoras0, 0, 0
chainguardtrivy-operator0
chainguardredpanda-operator*, *, *
wolfizarf0, 0, 0
chainguardconsul-k8s-1.7*, *, *
wolficilium-cli0, 0, 0
chainguardenvoy-gateway-fips-1.5*, *, *
chainguardcilium-cli0, 0, 0
wolfiopa0, 0, 0
chainguardflux-helm-controller-fips0, 0
wolfik8ssandra-client0, 0, 0
chainguarddrone0, 0, 0
chainguardchartmuseum-fips0

…and 137 more

Timeline

  • Jul 1, 2026 CVE Published
  • Jul 2, 2026 Security Advisory
  • Jul 18, 2026 EPSS Score
  • Jul 23, 2026 CVE Updated
  • Aug 7, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›