Path traversal in Podman - CVE-2026-79705
Published: September 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to overwrite arbitrary local files.
The vulnerability exists due to improper file path handling in the buildah/copier Go package when extracting maliciously crafted tar archives. A remote attacker can provide a maliciously crafted tar archive to overwrite arbitrary local files.
The issue is limited to uses outside the Buildah codebase by non-root or non-Linux users.