Impact
The vulnerability allows an attacker to perform arbitrary file writes outside the intended extraction directory when pulling OCI layers marked for unpacking. A specially crafted archive can create a symlink chain that appears internally valid but resolves to an attacker‑selected absolute path, enabling overwrite of any writable file. This enables data modification, disruption of services, and potential code execution by writing executable content to critical locations. The weakness is a classic path traversal error combined with insecure symlink handling, reflecting CWE-22 and CWE-59.
Affected Systems
The issue affects versions of the oras-go library prior to 2.6.2. Users running oras-go 2.6.1 or older are susceptible. The vulnerability is specific to the file.Store extraction process for OCI layers with the unpack flag set.
Risk and Exploitability
The CVSS score of 8.8 denotes high severity, while the EPSS score of less than 1% indicates low likelihood of current exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to supply a malicious OCI artifact and trigger its extraction; the attack vector is likely through known pull or import operations used by CI/CD or container build pipelines.
OpenCVE Enrichment
Github GHSA