CVE-2026-107174 PUBLISHED

Source-to-image: source-to-image: security boundary bypass via absolute symbolic link extraction

Assigner: redhat
Reserved: 07.10.2026 Published: 07.10.2026 Updated: 07.10.2026

A flaw was found in source-to-image. When unpacking archive files, the application fails to properly sanitize symbolic links pointing to absolute file paths. An attacker who supplies a malicious builder image can exploit this vulnerability by embedding links pointing outside the extraction directory. This allows the attacker to bypass sandbox boundaries, potentially leading to unauthorized information disclosure or file modification on the host system.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
CVSS Score: 6.4

Product Status

Vendor Red Hat
Product OpenShift Serverless
Versions Default: affected
Vendor Red Hat
Product OpenShift Serverless
Versions Default: affected
Vendor Red Hat
Product OpenShift Serverless
Versions Default: affected
Vendor Red Hat
Product OpenShift Source-to-Image (S2I)
Versions Default: affected
Vendor Red Hat
Product OpenShift Source-to-Image (S2I)
Versions Default: affected
Vendor Red Hat
Product Red Hat OpenShift Container Platform 4
Versions Default: affected
Vendor Red Hat
Product Red Hat OpenShift Container Platform 4
Versions Default: affected
Vendor Red Hat
Product Red Hat Web Terminal
Versions Default: affected

Workarounds

Treat s2i builder images and application source as trusted inputs. Do not run s2i-based builds against builder images or repositories you do not control or have not verified.

Where possible, run builds on isolated build nodes and restrict who can trigger builds or change BuildConfig and image stream references that point at custom builder images.

There is no configuration option to disable only this symlink extraction behavior without changing how builds are performed. Apply updated source-to-image packages or rebuilt platform images when Red Hat publishes them for your product and stream.

Credits

  • Red Hat would like to thank Yashashree Gund for reporting this issue.

References

Problem Types

  • UNIX Symbolic Link (Symlink) Following CWE