THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-m37j-52j7-pjw7 (high) — oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir)

[GHSA] GHSA-m37j-52j7-pjw7 (high) — oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir)

medgithub_advisoriesPublished 2026-09-17

GHSA-m37j-52j7-pjw7 Severity: high CVE: CVE-2026-85731

oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir)

### Summary The `content/file.Store` in oras-go v2 unpacks OCI layer tarballs when a descriptor carries `io.deis.oras.content.unpack=true`. The extraction routine validates symlink targets purely lexically (`filepath.Join`) and, for reg

Indicators of compromise

Original source: https://github.com/advisories/GHSA-m37j-52j7-pjw7