Impact
Melange builds APK packages from declarative pipelines. Affected Apko 1.2.9 and Melange 0.50.4 add a missing check: earlier versions verified only the control section (.PKGINFO etc.) against a signed APKINDEX but omitted verification of the data section containing the actual files that will be installed. If an attacker compromises a package mirror, poisons a cache, or performs a man‑in‑the‑middle attack while a package is fetched, they can replace those data section files with arbitrary content while the control hash check still succeeds. Once the package is installed on a target system, the substituted files can lead to arbitrary code execution or other malicious behaviors.
Affected Systems
Chainguard’s Apko tool versions before 1.2.9 and the Melange pipeline tool before 0.50.4 that build and distribute APK packages are affected the distributed version reaches the specific fixed releases; updated releases contain the fix.
Risk and Exploitability
The CVSS base score of 8.3 indicates a high severity vulnerability, yet the EPSS score of less than 1% suggests a very low probability of exploitation in current environments. The flaw is not listed in CISA KEV. Attackers can only exploit the weakness by tampering with the package distribution channel, so the vector is remote but requires control over or influence on an untrusted mirror or network. When succeeded, the possibility to replace arbitrary package files can provide an attacker with local code execution or data tampering on the systems that install the compromised packages.
OpenCVE Enrichment
Github GHSA