THREAT OPS › Threat News › [GHSA] GHSA-7h3g-4w2f-fj2f (high) — proot-distro has a Container Isolation Bypass via Crafted Restore Archive
[GHSA] GHSA-7h3g-4w2f-fj2f (high) — proot-distro has a Container Isolation Bypass via Crafted Restore Archive
GHSA-7h3g-4w2f-fj2f Severity: high CVE: CVE-2026-54727
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
## Affected Component
- **Package:** proot-distro - **Affected command:** `restore` - **Attack surface:** Host-side Termux CLI processing a user-supplied backup archive - **Vulnerability type:** Container Isolation Bypass / Cross-Container Read and Write
---
## Affe
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-54727cve
- https://packages-cf.termux.dev/apt/termux-mainurl
Original source: https://github.com/advisories/GHSA-7h3g-4w2f-fj2f