{"id":"GHSA-hfg8-hc9c-6c3h","summary":"moby/go-archive: Crafted tar archive can write outside the extraction directory","details":"### Summary\nThe tar extraction routines in `moby/go-archive` (`Unpack`, `UnpackLayer`, `Untar`/`UntarUncompressed`, and the `ApplyLayer` helpers) do not confine filesystem operations to the destination directory. A crafted archive can create or overwrite files **outside** the intended destination. \n\n### Details\nThe extractor decides where each archive entry lands using lexical string checks and then performs the filesystem operation on a path that is resolved by the OS, so a links introduced by the archive can be followed out of the destination directory.\n\n### Impact\nAn attacker who controls the contents of archive can create or overwrite files at arbitrary paths writable by the extracting process.\n\n### Workarounds\nOnly extract trusted archives.","aliases":["BIT-docker-cli-2026-17106","CVE-2026-17106","GO-2026-6253"],"modified":"2026-08-25T20:26:09.552171387Z","published":"2026-08-18T21:17:29Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-08-18T21:17:29Z","nvd_published_at":null,"cwe_ids":["CWE-22","CWE-59"]},"references":[{"type":"WEB","url":"https://github.com/moby/go-archive/security/advisories/GHSA-hfg8-hc9c-6c3h"},{"type":"WEB","url":"https://github.com/moby/moby/issues/52948"},{"type":"WEB","url":"https://docs.docker.com/desktop/release-notes/#4860"},{"type":"WEB","url":"https://github.com/bikini/exploitarium/tree/main/docker-cp-copyout-destination-escape"},{"type":"WEB","url":"https://github.com/docker/cli/releases/tag/v29.7.0"},{"type":"PACKAGE","url":"https://github.com/moby/go-archive"},{"type":"WEB","url":"https://github.com/moby/moby/releases/tag/docker-v29.7.0"},{"type":"WEB","url":"https://www.imperva.com/blog/copyescape-taking-over-docker-hosts-with-docker-cp"}],"affected":[{"package":{"name":"github.com/moby/go-archive","ecosystem":"Go","purl":"pkg:golang/github.com/moby/go-archive"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.3.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-hfg8-hc9c-6c3h/GHSA-hfg8-hc9c-6c3h.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}