A malicious builder peer may be able to request an in-context file by name from the host and receive the contents of whatever the name resolves to, even when it resolves outside the build context. This vulnerability is addressed in container version 1.2.0.
References
| Link | Resource |
|---|---|
| https://github.com/apple/container/security/advisories/GHSA-2v2q-4q35-h585 | Vendor Advisory Mitigation |
Configurations
History
No history.
Information
Published : 2026-08-20 19:16
Updated : 2026-08-27 20:09
NVD link : CVE-2026-64777
Mitre link : CVE-2026-64777
CVE.ORG link : CVE-2026-64777
JSON object : View
Products Affected
apple
- container
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
