A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching user. This happens before the sandboxed process starts. This issue is GHSA-pxhw-h44j-8pfx. It is fixed in bubblewrap 0.12.0.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-09 09:17
Updated : 2026-09-09 17:17
NVD link : CVE-2026-87766
Mitre link : CVE-2026-87766
CVE.ORG link : CVE-2026-87766
JSON object : View
Products Affected
No product.
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')
