Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-m37j-52j7-pjw7 | oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir) |
Fri, 18 Sep 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oras-project
Oras-project oras-go |
|
| Vendors & Products |
Oras-project
Oras-project oras-go |
Wed, 16 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, content/file.Store extraction of OCI layers marked with io.deis.oras.content.unpack=true can write outside the store working directory. The pushDir path through extractTarDirectory and ensureLinkPath validates symlink targets lexically, resolveRelToBase skips its parent-symlink walk for root-level entries, and writeFile follows a terminal symlink when opening a regular file. A malicious archive can therefore create a symlink chain whose lexical target remains inside the extraction root but whose resolved target is an attacker-selected absolute path, then overwrite that target with a same-named regular-file entry even when AllowPathTraversalOnWrite is false. Pulling an attacker-controlled artifact can create or overwrite any file writable by the process and may lead to code execution. This issue is fixed in version 2.6.2. | |
| Title | oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir) | |
| Weaknesses | CWE-22 CWE-59 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-16T17:25:07.159Z
Reserved: 2026-09-04T14:45:10.649Z
Link: CVE-2026-85731
Updated: 2026-09-16T17:24:41.115Z
Status : Deferred
Published: 2026-09-16T17:18:15.833
Modified: 2026-09-16T18:17:17.963
Link: CVE-2026-85731
No data.
OpenCVE Enrichment
Updated: 2026-09-18T04:30:03Z
Github GHSA