Description
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, content/file.Store extraction of OCI layers marked with io.deis.oras.content.unpack=true can write outside the store working directory. The pushDir path through extractTarDirectory and ensureLinkPath validates symlink targets lexically, resolveRelToBase skips its parent-symlink walk for root-level entries, and writeFile follows a terminal symlink when opening a regular file. A malicious archive can therefore create a symlink chain whose lexical target remains inside the extraction root but whose resolved target is an attacker-selected absolute path, then overwrite that target with a same-named regular-file entry even when AllowPathTraversalOnWrite is false. Pulling an attacker-controlled artifact can create or overwrite any file writable by the process and may lead to code execution. This issue is fixed in version 2.6.2.
Published: 2026-09-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Write (potential code execution)
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an attacker to perform arbitrary file writes outside the intended extraction directory when pulling OCI layers marked for unpacking. A specially crafted archive can create a symlink chain that appears internally valid but resolves to an attacker‑selected absolute path, enabling overwrite of any writable file. This enables data modification, disruption of services, and potential code execution by writing executable content to critical locations. The weakness is a classic path traversal error combined with insecure symlink handling, reflecting CWE-22 and CWE-59.

Affected Systems

The issue affects versions of the oras-go library prior to 2.6.2. Users running oras-go 2.6.1 or older are susceptible. The vulnerability is specific to the file.Store extraction process for OCI layers with the unpack flag set.

Risk and Exploitability

The CVSS score of 8.8 denotes high severity, while the EPSS score of less than 1% indicates low likelihood of current exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to supply a malicious OCI artifact and trigger its extraction; the attack vector is likely through known pull or import operations used by CI/CD or container build pipelines.

Generated by OpenCVE AI on September 18, 2026 at 02:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade oras-go to version 2.6.2 or later.
  • If upgrade is not immediately possible, restrict OCI layer extraction to only trusted, signed artifacts and validate them before unpacking.
  • Run oras-go processes as a non‑privileged user with limited file permissions to reduce the impact of a successful exploit.
  • Consider disabling or monitoring the AllowPathTraversalOnWrite option to prevent unintended writes during extraction.

Generated by OpenCVE AI on September 18, 2026 at 02:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-m37j-52j7-pjw7 oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir)
History

Fri, 18 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Oras-project
Oras-project oras-go
Vendors & Products Oras-project
Oras-project oras-go

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, content/file.Store extraction of OCI layers marked with io.deis.oras.content.unpack=true can write outside the store working directory. The pushDir path through extractTarDirectory and ensureLinkPath validates symlink targets lexically, resolveRelToBase skips its parent-symlink walk for root-level entries, and writeFile follows a terminal symlink when opening a regular file. A malicious archive can therefore create a symlink chain whose lexical target remains inside the extraction root but whose resolved target is an attacker-selected absolute path, then overwrite that target with a same-named regular-file entry even when AllowPathTraversalOnWrite is false. Pulling an attacker-controlled artifact can create or overwrite any file writable by the process and may lead to code execution. This issue is fixed in version 2.6.2.
Title oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir)
Weaknesses CWE-22
CWE-59
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oras-project Oras-go
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T17:25:07.159Z

Reserved: 2026-09-04T14:45:10.649Z

Link: CVE-2026-85731

cve-icon Vulnrichment

Updated: 2026-09-16T17:24:41.115Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T17:18:15.833

Modified: 2026-09-16T18:17:17.963

Link: CVE-2026-85731

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T04:30:03Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')