Symlink Vulnerability in Aqua Version Manager Affects Package Extraction
CVE-2026-55569

6.6MEDIUM

Key Information:

Vendor

Aquaproj

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-55569?

Aqua, a declarative command-line version manager, is susceptible to a symlink vulnerability due to improper validation of symlink targets during archive extraction. When an attacker crafts a malicious package archive, the application may unwittingly write files outside its designated extraction directory. This occurs because the target of a symlink may point to a location beyond Aqua's control, allowing unauthorized modifications to occur, such as overwriting critical shell startup files or configuration settings. The issue has been addressed in Aqua version 2.60.1.

Affected Version(s)

aqua < 2.60.1

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.