CVE-2026-54574

HIGH

`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive

Title source: cna
STIX 2.1

Description

proot-distro is a utility for managing proot containers. Prior to version 5.1.5, proot-distro install extracted plain tarball root filesystems through _extract_plain_tar() in proot_distro/commands/install.py and Docker layers through _apply_layer() in proot_distro/helpers/docker.py without validating archive-controlled symlink targets in member.linkname, allowing a malicious archive to plant an absolute host-path symlink and write files through it onto the host filesystem. This issue is fixed in version 5.1.5.

Scores

CVSS v3 8.2
EPSS 0.0014
EPSS Percentile 4.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-61
Status published
Products (2)
pypi/proot-distro 0 - 5.1.5PyPI
termux/proot-distro < 5.1.5
Published Jul 29, 2026
Tracked Since Jul 29, 2026