PT-2026-93848 · Oras-Go · Oras-Go
CVE-2026-85731
·
Published
2026-07-10
·
Updated
2026-10-02
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
oras-go versions prior to 2.6.2
Description
An issue in the
content/file.Store component of the oras-go library allows for arbitrary file creation or overwrite outside the intended working directory. This occurs when extracting OCI layers marked with io.deis.oras.content.unpack=true. The flaw stems from the pushDir path, specifically within the extractTarDirectory() and ensureLinkPath() functions, which validate symlink targets lexically rather than resolving them. Additionally, the resolveRelToBase() function skips parent-symlink checks for root-level entries, and the writeFile() function follows terminal symlinks when opening regular files.An attacker can craft a malicious archive containing a symlink chain that appears to stay within the extraction root during lexical validation but resolves to an absolute path on the host system. By following this with a regular-file entry of the same name, the attacker can overwrite any file writable by the process, even if
AllowPathTraversalOnWrite is set to false. This can lead to remote code execution (RCE) by overwriting critical system files or configuration files.Recommendations
Update oras-go to version 2.6.2.
Exploit
Fix
RCE
Link Following
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oras-Go