cbcvebase.
CVE-2026-20613
published 2026-01-23

CVE-2026-20613: The ArchiveReader.extractContents() function used by cctl image load and container image load performs no pathname validation before extracting an archive…

PriorityP339high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.25%
16.0th percentile
The ArchiveReader.extractContents() function used by cctl image load and container image load performs no pathname validation before extracting an archive member. This means that a carelessly or maliciously constructed archive can extract a file into any user-writable location on the system using relative pathnames. This issue is addressed in container 0.8.0 and containerization 0.21.0.

Affected

6 ranges
VendorProductVersion rangeFixed in
applecontainer< 0.8.00.8.0
applecontainer>= unspecified < 0.7.10.7.1
applecontainerization< 0.21.00.21.0
applecontainerization>= unspecified < 0.20.10.20.1
github.comapple_container>= 0 < 0.8.00.8.0
github.comapple_containerization>= 0 < 0.21.00.21.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.