CVE-2026-107174: Source-to-image: source-to-image: security boundary bypass via absolute symbolic link extraction
A flaw was found in openshift/source-to-image's paranoid tar extraction mode (NewParanoid). The extractLink() function in pkg/tar/tar.go validates that a symlink target stays inside the extraction directory by computing a sanitized path using filepath.Clean(filepath.Join(dest, "..", source)), but then creates the actual symlink using the raw, unvalidated header.Linkname via os.Symlink(source, dest). For relative symlink traversals this check works correctly because filepath.Join resolves ".." components. However, for absolute Linkname values (e.g. "/etc/passwd"), Go's filepath.Join does not re-root, so the sanitized path folds harmlessly under the jail directory and passes the check, while the actual symlink points to the attacker-specified absolute host path. This bypasses the security boundary introduced to fix CVE-2018-1103. The paranoid mode is used by s2i's primary build strategy, including paths that extract tar streams produced by attacker-controlled builder image scripts (save-artifacts, assemble). A malicious builder image can plant symlinks pointing to arbitrary absolute host paths outside the sandbox directory.
Other sources
A flaw was found in source-to-image. When unpacking archive files, the application fails to properly sanitize symbolic links pointing to absolute file paths. An attacker who supplies a malicious builder image can exploit this vulnerability by embedding links pointing outside the extraction directory. This allows the attacker to bypass sandbox boundaries, potentially leading to unauthorized information disclosure or file modification on the host system.
— MITRE
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Users of source-to-image builds that process tar streams from attacker-controlled builder image scripts are exposed. The affected paths include the primary build strategy and scripts such as save-artifacts and assemble.
What does an attacker need to exploit the flaw?
An attacker needs the ability to supply or control a builder image that produces a malicious tar archive. The archive must contain a symbolic link with an absolute target path, such as /etc/passwd.
Are ordinary relative symlink traversal payloads affected by this bypass?
The described validation correctly handles relative traversal components because filepath.Join resolves ".." components. The bypass specifically relies on absolute symbolic-link targets, which pass validation but are created using the raw target value.
What can exploitation achieve?
A malicious builder image can cause extraction to create symlinks to arbitrary absolute host paths outside the intended sandbox directory. This bypasses the extraction security boundary established for CVE-2018-1103.