GO-2026-6253
Dashboard / Vulnerabilities / GO-2026-6253
Summary: moby/go-archive: Crafted tar archive can write outside the extraction directory in github.com/moby/go-archive
Details: moby/go-archive: Crafted tar archive can write outside the extraction directory in github.com/moby/go-archive
References: https://github.com/moby/go-archive/security/advisories/GHSA-hfg8-hc9c-6c3h, https://docs.docker.com/desktop/release-notes/#4860, https://github.com/bikini/exploitarium/tree/main/docker-cp-copyout-destination-escape, https://github.com/docker/cli/releases/tag/v29.7.0, https://github.com/moby/moby/issues/52948, https://github.com/moby/moby/releases/tag/docker-v29.7.0, https://www.imperva.com/blog/copyescape-taking-over-docker-hosts-with-docker-cp
Affected packages
Package
Name: github.com/moby/go-archive
Purl: pkg:golang/github.com/moby/go-archive
Affected ranges
Type: SEMVER
Events:
