THREAT OPS › Threat News › [GHSA] GHSA-m37j-52j7-pjw7 (high) — oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir)
[GHSA] GHSA-m37j-52j7-pjw7 (high) — oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir)
GHSA-m37j-52j7-pjw7 Severity: high CVE: CVE-2026-85731
oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir)
### Summary The `content/file.Store` in oras-go v2 unpacks OCI layer tarballs when a descriptor carries `io.deis.oras.content.unpack=true`. The extraction routine validates symlink targets purely lexically (`filepath.Join`) and, for reg
Indicators of compromise
- CVE-2026-85731cve
- CVE-2026-50162cve
Original source: https://github.com/advisories/GHSA-m37j-52j7-pjw7