{"id":"CVE-2026-50162","aliases":["GHSA-8xwf-rjm4-xvhv","GO-2026-5879"],"url":"https://o3.security/vulnerability/CVE-2026-50162","summary":"oras-go: file store write outside workingDir via symlink traversal","details":"oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, resolveWritePath() in content/file/file.go uses a lexical filepath.Rel check for workingDir and does not account for symlink traversal, so when AllowPathTraversalOnWrite=false an attacker-controlled blob title through ocispec.AnnotationTitle such as out/pwn.txt can follow a workingDir symlink out -> /some/outside/dir and cause pushFile() to create /some/outside/dir/pwn.txt outside workingDir. This issue is fixed in version 2.6.1.","published":"2026-07-17T19:39:28.847Z","modified":"2026-08-27T18:26:14.541769608Z","cvss":null,"epss":{"score":0.00507,"percentile":0.41427,"asOf":"2026-09-07"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"oras.land/oras-go/v2","fixedVersion":"2.6.1"}],"fix":{"url":"https://github.com/oras-project/oras-go/commit/cc323e564d90c6b5b4bdd71d3c8d2ee2713b37e5","label":"oras-project/oras-go@cc323e5"},"references":[{"type":"WEB","url":"https://github.com/oras-project/oras-go/releases/tag/v2.6.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/50xxx/CVE-2026-50162.json"},{"type":"ADVISORY","url":"https://github.com/oras-project/oras-go/security/advisories/GHSA-8xwf-rjm4-xvhv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50162"},{"type":"FIX","url":"https://github.com/oras-project/oras-go/commit/cc323e564d90c6b5b4bdd71d3c8d2ee2713b37e5"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T18:26:14.541769608Z"}}