{"id":"GO-2026-6499","summary":"Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir) in oras.land/oras-go","details":"Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir) in oras.land/oras-go","aliases":["CVE-2026-85731","GHSA-m37j-52j7-pjw7"],"modified":"2026-10-01T20:45:11.282988734Z","published":"2026-10-01T20:23:52Z","database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-6499"},"references":[{"type":"ADVISORY","url":"https://github.com/oras-project/oras-go/security/advisories/GHSA-m37j-52j7-pjw7"},{"type":"WEB","url":"https://github.com/oras-project/oras-go/commit/adab2f25ea95ef4e6e41f50db9266a6701399422"},{"type":"WEB","url":"https://github.com/oras-project/oras-go/releases/tag/v2.6.2"}],"affected":[{"package":{"name":"oras.land/oras-go/v2","ecosystem":"Go","purl":"pkg:golang/oras.land/oras-go/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.6.2"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-6499.json"}}],"schema_version":"1.9.0"}