CVE-2026-24844: melange pipeline working-directory could allow command injection
An attacker who can provide build input values, but not modify pipeline definitions, could execute arbitrary shell commands if the pipeline uses ${{vars.}} or ${{inputs.}} substitutions in working-directory. The field is embedded into shell scripts without proper quote escaping.
Fix: Fixed with e51ca30c, Released.
Acknowledgements
melange thanks Oleh Konko from 1seal for discovering and reporting this issue.
Other sources
melange allows users to build apk packages using declarative pipelines. From version 0.3.0 to before 0.40.3, an attacker who can provide build input values, but not modify pipeline definitions, could execute arbitrary shell commands if the pipeline uses ${{vars.}} or ${{inputs.}} substitutions in working-directory. The field is embedded into shell scripts without proper quote escaping. This issue has been patched in version 0.40.3.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24844?
CVE-2026-24844 is rated as a critical vulnerability due to the potential for arbitrary command execution.
How do I fix CVE-2026-24844?
To fix CVE-2026-24844, update to the latest version of the melange package, ideally version 0.40.4 or later.
Who is affected by CVE-2026-24844?
Any user or organization utilizing versions of the melange pipeline from 0.3.0 to 0.40.3 is affected by CVE-2026-24844.
What types of attacks can be executed through CVE-2026-24844?
CVE-2026-24844 allows attackers to execute arbitrary shell commands through manipulating input values.
Is CVE-2026-24844 related to specific programming languages or platforms?
CVE-2026-24844 specifically impacts applications written in Go that utilize the chainguard.dev/melange package.