PT-2026-93848 · Oras-Go · Oras-Go

CVE-2026-85731

·

Published

2026-07-10

·

Updated

2026-10-02

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions oras-go versions prior to 2.6.2
Description An issue in the content/file.Store component of the oras-go library allows for arbitrary file creation or overwrite outside the intended working directory. This occurs when extracting OCI layers marked with io.deis.oras.content.unpack=true. The flaw stems from the pushDir path, specifically within the extractTarDirectory() and ensureLinkPath() functions, which validate symlink targets lexically rather than resolving them. Additionally, the resolveRelToBase() function skips parent-symlink checks for root-level entries, and the writeFile() function follows terminal symlinks when opening regular files.
An attacker can craft a malicious archive containing a symlink chain that appears to stay within the extraction root during lexical validation but resolves to an absolute path on the host system. By following this with a regular-file entry of the same name, the attacker can overwrite any file writable by the process, even if AllowPathTraversalOnWrite is set to false. This can lead to remote code execution (RCE) by overwriting critical system files or configuration files.
Recommendations Update oras-go to version 2.6.2.

Exploit

Fix

RCE

Link Following

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14836
CVE-2026-85731
GHSA-M37J-52J7-PJW7
GO-2026-6499
OPENSUSE-SU-2026:11832-1
SUSE-SU-2026:4417-1

Affected Products

Oras-Go