Impact
The flaw in operator‑foundry’s resolveAndValidatePath uses only lexical containment checks, ignoring symbolic links. An attacker can place a symlink inside the build context that points to a file or directory outside the intended boundary, thereby obtaining unauthorized access to sensitive resources beyond the confined environment.
Affected Systems
This vulnerability affects installations of operator‑foundry. The specific affected versions are not enumerated in the advisory, so all variants that employ the current resolveAndValidatePath logic are potentially susceptible.
Risk and Exploitability
The CVSS score of 2.6 indicates low impact, and the EPSS score is unavailable, so current exploitation probability is unclear. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploits. Nevertheless, the attack vector is local or could be triggered during a build process, allowing an adversary with write access to the build context to read arbitrary files outside the context by exploiting the symlink bypass.
OpenCVE Enrichment