THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-9xq3-3fqg-4vg7 (high) — `proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive

[GHSA] GHSA-9xq3-3fqg-4vg7 (high) — `proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive

highgithub_advisoriesPublished 2026-07-29

GHSA-9xq3-3fqg-4vg7 Severity: high CVE: CVE-2026-54574

`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive

**Repository:** `termux/proot-distro` **Component:** `proot_distro/commands/install.py` → `_extract_plain_tar()`; also `helpers/docker.py` → `_apply_layer()`

---

## Affected Versions

| Component | Version | |---

Indicators of compromise

Original source: https://github.com/advisories/GHSA-9xq3-3fqg-4vg7