PT-2026-83253 · Aqua · Aqua

CVE-2026-55569

·

Published

2026-08-28

·

Updated

2026-09-08

CVSS v3.1

6.6

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions aqua versions prior to 2.60.1
Description In the (*handler).HandleFile function within pkg/unarchive/archives.go, the software fails to verify that the target of a symlink created via os.Symlink remains within the intended extraction destination. A malicious archive can create a symlink to a location outside the extraction directory, and a subsequent regular-file entry at the same path opened with OpenFile using O CREATE and O WRONLY will follow that symlink. This allows an attacker to write controlled bytes to arbitrary locations on the filesystem with the privileges of the user running the application, potentially overwriting shell startup files, tool configurations, or writable executable paths.
Recommendations Update aqua to version 2.60.1.

Exploit

Fix

Path traversal

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55569
GHSA-MF5C-HW34-4HPP
GO-2026-6314
OPENSUSE-SU-2026:21812-1

Affected Products

Aqua