Link following in Bubblewrap - #VU145997

 

Link following in Bubblewrap - #VU145997

Published: August 27, 2026


Vulnerability identifier: #VU145997
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-59
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to write files outside the sandbox.

The vulnerability exists due to improper link resolution before file access in the bubblewrap sandbox setup logic when creating files or directories on attacker-controlled filesystem content. A local user can use symlinks that redirect through /oldroot to write files outside the sandbox.

This issue occurs during sandbox setup before anything is running inside the sandbox, and exploitation requires bubblewrap to create files on attacker-controlled filesystem content such as a malicious app image.


Affected software

Bubblewrap

Remediation

Install security update from vendor's website.

Bubblewrap - update to 0.12.0

External References

Related Security Bulletins