CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-54727

CVE-2026-54727: Container Isolation Bypass in proot-distro via Malicious Restore Archive

Amit Schendel
Amit Schendel
Senior Security Researcher

Jul 30, 2026·5 min read·28 visits

Executive Summary (TL;DR)

A container boundary bypass in proot-distro allows a malicious restore archive to read or write files inside other isolated containers on the device.

A container isolation bypass vulnerability exists in proot-distro prior to version 5.1.6. The utility accepted hardlink entries pointing outside the container directory being restored, allowing cross-container file read and write capabilities.

Vulnerability Overview

The vulnerability designated as CVE-2026-54727 is a container isolation bypass in proot-distro before version 5.1.6. This utility manages PRoot-based rootless Linux distributions on Termux. Because all containers in this environment execute under the context of the same Termux Unix user ID, they share physical host permissions. The security boundary between containers is primarily maintained by path segregation within the application logic.

During the execution of the restore command, proot-distro extracts user-provided backup tarballs. Prior to version 5.1.6, the extraction engine failed to ensure that hardlink targets resolved exclusively within the specific container being restored. This omission allowed a malicious or compromised container archive to reference resources belonging to other separate containers, undermining the intended tenant isolation model.

Root Cause Analysis

The root cause lies in how the proot-distro restore process parsed TAR archive files containing hardlinks (tarfile.LNKTYPE). When the Python tarfile module or helper functions extract a hardlink, they resolve the target path indicated by the linkname property relative to the working directory. While proot-distro restricted links from escaping the overall directory containing all containers, it did not enforce isolation at the individual container level.

Specifically, the program did not cross-reference the container name extracted from the destination path with the container name defined in the link's source. If the destination was set to attacker-container/rootfs/... and the link's target path was ../victim-container/rootfs/..., the underlying OS hardlink call would succeed because both paths were owned by the same Termux user ID.

Additionally, a secondary input validation weakness existed in the name validation regex defined in names.py. The expression re.compile(r"^[A-Za-z0-9][A-Za-z0-9_.\-]*$") used the $ anchor instead of \Z. In Python, the $ anchor permits a trailing newline character (\n) at the end of the validated string. This enabled the creation of container names containing hidden control characters, which could lead to command injection or filesystem state confusion during path rendering.

Code Analysis

The fix for CVE-2026-54727 was implemented across several commits to enforce strict container boundaries. Commit 98aff324b7d8500ff75a8ca9ac087ee636be4716 introduced hardlink target verification during the extraction process. The following diff demonstrates how the target container name of a hardlink is extracted and validated against the active container restoration context:

# Mitigation: Enforcing that hardlink sources match the active container
link_container, link_src = _dest_path(member.linkname)
if link_src is None or link_container != restore_name:
    # Skip hardlinks pointing outside the target container
    continue

Additionally, the container name validation was hardened in commit eb1dbf8d204c8cb494e8787b935d170a802675d5 by changing the end-of-string match anchor to prevent trailing newline bypasses:

# Patched pattern using \Z
_NAME_RE = re.compile(r"^[A-Za-z0-9][A-Za-z0-9_.\-]*\Z")

Commit 6f73f98330b576dfc6863b9c5ad5043d043c8609 also added a helper _is_rootfs_dest to verify that the target directory resolves to the expected rootfs location of the current container. This prevents files from overwriting metadata files or other internal files during extraction.

Exploitation Methodology

An attacker can exploit this flaw by constructing a TAR archive that masquerades as a legitimate container backup. The archive contains a manifest.json file configuring a target container named attacker-box and a matching directory structure under attacker-box/rootfs/. To bridge the isolation boundary, the attacker inserts a hardlink record (tarfile.LNKTYPE) into the archive stream.

The hardlink maps a source entry inside attacker-box/rootfs/sensitive to a target file located in an unrelated container directory, such as ../victim-box/rootfs/etc/shadow. Since the extractor does not check if the prefix of the resolved target matches attacker-box, the extraction utility calls os.link(). This creates a direct reference link to the victim container's sensitive file, giving the attacker read and write access to the target file when they interact with attacker-box.

Impact Assessment

The CVSS score of 8.2 (High) reflects the severity of this container containment failure. The vulnerability scores High for Confidentiality and Integrity impacts because an attacker can gain arbitrary read and write access to any file inside other isolated containers managed by the same Termux installation. If the victim container runs databases, local configuration stores, or cryptographic keys, these assets are fully compromised.

The Attack Vector is Local (AV:L) because the victim must be enticed to run the proot-distro restore command on an untrusted archive. This makes social engineering or supply-chain delivery of malicious container configurations the primary threat vectors. The Scope is Changed (S:C) because a vulnerability in the restore engine of one container breaches the integrity and confidentiality boundaries of other tenant environments.

Remediation and Mitigation Guidance

The primary remediation for CVE-2026-54727 is updating proot-distro to version 5.1.6 or later. This release enforces single-container restore boundaries, checks the validity of extraction paths, and restricts hardlinks to their respective container roots. The package can be updated using the Termux package manager.

In environments where immediate updates are not feasible, administrators should refrain from restoring third-party or untrusted container backup archives. System integrators should audit existing backup files by executing command-line inspections. Inspecting the archive contents before executing a restore will reveal if any hardlink or symlink members attempt to traverse out of the target directory structure.

tar -tvf container_backup.tar.gz | grep -E "-> \.\./"

Fix Analysis (4)

Technical Appendix

CVSS Score
8.2/ 10
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Affected Systems

proot-distro

Affected Versions Detail

Product
Affected Versions
Fixed Version
proot-distro
Termux
< 5.1.65.1.6
AttributeDetail
CWE IDCWE-668
Attack VectorLocal
CVSS Score8.2 (High)
ImpactCross-container read and write access
Exploit StatusProof-of-Concept
KEV StatusNot Listed

MITRE ATT&CK Mapping

T1190Exploit Public-Facing Application
Initial Access
T1005Data from Local System
Collection
CWE-668
Exposure of Resource to Wrong Sphere

The software does not prevent the transfer of a resource from a private sphere into an untrusted sphere.

Known Exploits & Detection

GitHub Security AdvisoryDetails the logical flaw concerning hardlink destination validation inside rootless container environments.

References & Sources

  • [1]GitHub Security Advisory (GHSA-7h3g-4w2f-fj2f)
  • [2]proot-distro v5.1.6 Release Notes

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•27 minutes ago•GHSA-P23F-CM6Q-2QP8
8.6

GHSA-P23F-CM6Q-2QP8: Workspace Boundary Bypass and Arbitrary File Leak in SiYuan MCP

SiYuan is an open-source personal knowledge management system. Its Model Context Protocol (MCP) implementation within the asset.upload tool contains a path-traversal and workspace boundary bypass flaw. This allows remote AI models—acting on behalf of attackers via malicious prompts or documents—to import and read sensitive host-system files, such as private keys and system configurations, through absolute path inputs.

Alon Barad
Alon Barad
2 views•6 min read
•about 1 hour ago•GHSA-X8GV-G2G3-65FJ
8.2

CVE-2026-82234: Server-Side Request Forgery via DNS-Rebinding TOCTOU in SiYuan Kernel

An Server-Side Request Forgery (SSRF) vulnerability via DNS-Rebinding Time-of-Check to Time-of-Use (TOCTOU) has been discovered in SiYuan (思源笔记), an open-source personal knowledge management system. The flaw exists within the AI Agent tools http_request (util.HTTPRequest) and web_fetch (util.WebFetch) of the SiYuan Kernel, allowing unauthenticated remote attackers to bypass SSRF validation and access private internal services or cloud metadata endpoints.

Amit Schendel
Amit Schendel
4 views•7 min read
•about 2 hours ago•CVE-2026-104861
7.5

CVE-2026-104861: Quadratic-time Regular Expression Denial of Service in probe-image-size SVG Parser

An uncontrolled resource consumption vulnerability (CWE-1333 / CWE-400) exists in probe-image-size versions prior to 7.4.0. The SVG parser utilizes an unanchored, inefficient regular expression to find the SVG root tag, leading to catastrophic backtracking when handling malformed payloads. This blocks the single-threaded Node.js event loop, resulting in a complete denial of service.

Amit Schendel
Amit Schendel
5 views•9 min read
•about 3 hours ago•CVE-2026-10032
6.1

CVE-2026-10032: DOM-based Cross-Site Scripting (XSS) via window.open in Google @a2ui/web_core

CVE-2026-10032 is a DOM-based Cross-Site Scripting (XSS) vulnerability in Google's @a2ui/web_core Node.js library. The vulnerability is located within the openUrl utility function, which processes and opens dynamic URLs defined in layout configurations. Because the function fails to sanitize or validate the target URL scheme before passing it to the window.open browser sink, an attacker can specify a javascript: pseudo-protocol to execute arbitrary client-side script in the context of the host origin.

Amit Schendel
Amit Schendel
7 views•7 min read
•about 4 hours ago•CVE-2026-59944
6.1

CVE-2026-59944: Path Traversal and Symlink Resolution Bypass in Composer

CVE-2026-59944 is a path traversal and link-following vulnerability in Composer, the PHP dependency manager. This flaw allows malicious or compromised packages to bypass previous path-hardening protections and perform arbitrary filesystem operations outside of their designated installation directory, leading to unauthorized permission modifications or execution proxy creations.

Amit Schendel
Amit Schendel
7 views•6 min read
•about 5 hours ago•GHSA-QXPP-QJG8-X4JV
9.9

GHSA-QXPP-QJG8-X4JV: Cross-Tenant Run Replay and Task Injection in Trigger.dev

A critical Broken Object Level Authorization (BOLA) vulnerability was identified in Trigger.dev before version v4.5.2. An authenticated attacker could trigger a run replay and supply an arbitrary target environmentId belonging to a completely different tenant. Because the server failed to validate whether the target environment belonged to the same project or organization as the source run, it would execute the task within the victim's environment, resulting in unauthorized cross-tenant write operations and remote task execution.

Alon Barad
Alon Barad
10 views•5 min read