Description
apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before version 1.2.5, a crafted .apk could install a TypeSymlink tar entry whose target pointed outside the build root, and a subsequent directory-creation or file-write entry in the same or later archive could traverse that symlink to reach host paths the build user could write to. This issue has been patched in version 1.2.5.
References (4)
Core 4
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/chainguard-dev/apko/security/advisories/GHSA-qq3r-w4hj-gjp6
X_Refsource_Misc x_refsource_misc
https://github.com/chainguard-dev/apko/pull/2187
X_Refsource_Misc x_refsource_misc
https://github.com/chainguard-dev/apko/commit/f5a96e1299ac81c7ea9441705ec467688086f442
X_Refsource_Misc x_refsource_misc
https://github.com/chainguard-dev/apko/releases/tag/v1.2.5
Scores
CVSS v3
7.5
EPSS
0.0035
EPSS Percentile
26.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-22
CWE-59
Status
published
Products (2)
chainguard-dev/apko
>= 0.14.8, < 1.2.5
chainguard.dev/apko
0.14.8 - 1.2.5Go
Published
May 09, 2026
Tracked Since
May 10, 2026