Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-2w4f-9fgg-q2v9 | melange has a path traversal in license-path which allows reading files outside workspace |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 05 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 05 Feb 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chainguard-dev
Chainguard-dev melange |
|
| Vendors & Products |
Chainguard-dev
Chainguard-dev melange |
Wed, 04 Feb 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | melange allows users to build apk packages using declarative pipelines. From version 0.14.0 to before 0.40.3, an attacker who can influence a melange configuration file (e.g., through pull request-driven CI or build-as-a-service scenarios) could read arbitrary files from the host system. The LicensingInfos function in pkg/config/config.go reads license files specified in copyright[].license-path without validating that paths remain within the workspace directory, allowing path traversal via ../ sequences. The contents of the traversed file are embedded into the generated SBOM as license text, enabling exfiltration of sensitive data through build artifacts. This issue has been patched in version 0.40.3. | |
| Title | melange has a path traversal in license-path which allows reading files outside workspace | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-05T14:32:56.438Z
Reserved: 2026-01-29T15:39:11.821Z
Link: CVE-2026-25145
Updated: 2026-02-05T14:20:16.972Z
Status : Awaiting Analysis
Published: 2026-02-04T20:16:06.373
Modified: 2026-02-05T14:57:20.563
Link: CVE-2026-25145
No data.
OpenCVE Enrichment
Updated: 2026-02-05T11:39:40Z
Github GHSA