Description

kaniko is a tool to build container images from a Dockerfile, inside a container or Kubernetes cluster. Starting in version 1.25.4 and prior to version 1.25.10, kaniko unpacks build context archives using `filepath.Join(dest, cleanedName)` without enforcing that the final path stays within `dest`. A tar entry like `../outside.txt` escapes the extraction root and writes files outside the destination directory. In environments with registry authentication, this can be chained with docker credential helpers to achieve code execution within the executor process. Version 1.25.10 uses securejoin for path resolution in tar extraction.

INFO

Published Date :

2026-02-27T21:20:52.764Z

Last Modified :

2026-03-02T22:00:32.356Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-28406 vulnerability.

Vendors Products
Chainguard
  • Kaniko
Chainguard-forks
  • Kaniko

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact