CVE-2026-24846: malcontent's archive extraction could write outside extraction directory

Published Jan 29, 2026
·
Updated

malcontent could be made to create symlinks outside the intended extraction directory when scanning a specially crafted tar or deb archive. The handleSymlink function received arguments in the wrong order, causing the symlink target to be used as the symlink location. Additionally, symlink targets were not validated to ensure they resolved within the extraction directory.

Fixes: - Swap handleSymlink arguments; validate symlink location - Validate symlink targets resolve within extraction directory

Acknowledgements

Thank you to Oleh Konko from 1seal for discovering and reporting this issue.

Other sources

malcontent discovers supply-chain compromises through. context, differential analysis, and YARA. Starting in version 1.8.0 and prior to version 1.20.3, malcontent could be made to create symlinks outside the intended extraction directory when scanning a specially crafted tar or deb archive. The handleSymlink function received arguments in the wrong order, causing the symlink target to be used as the symlink location. Additionally, symlink targets were not validated to ensure they resolved within the extraction directory. Version 1.20.3 introduces fixes that swap handleSymlink arguments, validate symlink location, and validate symlink targets that resolve within an extraction directory.

— MITRE

Affected Software

3 affected componentsFixes available
npm/malcontent>1.8.0<=1.20.3
go/github.com/chainguard-dev/malcontent>=1.8.0<1.20.3
1.20.3
chainguard malcontent>=1.8.0<1.20.3

Event History

Jan 29, 2026
CVE Published
via MITRE·09:12 PM
Data Sourced
via MITRE·09:12 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·10:05 PM
Data Sourced
via GitHub·10:05 PM
DescriptionSeverityWeaknessAffected Software
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
RemedyAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-24846?

CVE-2026-24846 is categorized as a high severity vulnerability due to its potential to create symlinks outside the intended extraction directory.

2

How do I fix CVE-2026-24846?

To fix CVE-2026-24846, upgrade to malcontent version 1.20.3 or higher.

3

What types of archives are affected by CVE-2026-24846?

CVE-2026-24846 affects tar and deb archive files that are scanned by malcontent.

4

Who is impacted by CVE-2026-24846?

Users of the malcontent package versions between 1.8.0 and 1.20.3 are impacted by CVE-2026-24846.

5

What is the nature of the vulnerability described in CVE-2026-24846?

The vulnerability in CVE-2026-24846 allows malcontent to create symlinks outside the designated extraction directory due to incorrect handling of function arguments.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203