Source-to-Image Vulnerability in Red Hat's Application Development Tools
CVE-2026-107174
6.4MEDIUM
What is CVE-2026-107174?
A vulnerability exists in Red Hat's source-to-image tool which improperly sanitizes symbolic links during the unpacking of archive files. This flaw allows an attacker to craft a malicious builder image containing symbolic links that point to absolute paths outside of the intended extraction directory. By exploiting this weakness, the attacker can bypass sandbox restrictions, leading to potential unauthorized information disclosure or modifications to files on the host system.
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Yashashree Gund for reporting this issue.