Symlink Vulnerability in Bubblewrap by Container Solutions
CVE-2026-87766
8.8HIGH
What is CVE-2026-87766?
A vulnerability exists in Bubblewrap that allows for unauthorized file creation outside of its sandbox environment. During the setup of a sandbox, the application improperly handles symlinks, allowing attackers to escape the sandbox and write to arbitrary file paths on the host system. This security flaw occurs before the sandboxed process begins execution, raising significant concerns regarding the integrity and security of applications relying on Bubblewrap for isolation. The issue has been documented under GHSA-pxhw-h44j-8pfx and was resolved in version 0.12.0.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank geeknik for reporting this issue.