Security Advisory

CVE-2026-79705

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-15 16:23:26
Last updated 2026-09-15 17:58:45
Assigner redhat
CVSS score 4.5
State PUBLISHED

Description

A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archive containing malicious symlinks can escape the target extraction directory and create files outside the intended destination. Buildah itself uses chroot hardening and is not affected.