Shell Command Injection Vulnerability in Melange by Chainguard
CVE-2026-25143
What is CVE-2026-25143?
The Melange software, developed by Chainguard, allows users to create APK packages utilizing declarative pipelines. A vulnerability exists in versions from 0.10.0 to just before 0.40.3, where an attacker can influence the inputs to the patch pipeline. This can lead to the execution of arbitrary shell commands on the build host due to inadequate quoting and validation of user-supplied values. The built-in patch pipeline, which is engaged during melange build and license-check operations, enables successful exploitation if attackers control patch-related inputs, such as during continuous integration workflows or configuration modifications. Attackers can leverage shell metacharacters to execute commands with the same privileges as the Melange build process. Version 0.40.3 has addressed this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
melange >= 0.10.0, < 0.40.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
