← Vulnerability feed

Vulnerability record · CVE-2026-20613 · published 23 January 2026

CVE-2026-20613: Apple container path traversal vulnerability

Apple · Container

The ArchiveReader.extractContents() function used by cctl image load and container image load performs no pathname validation before extracting an archive member. This means that a carelessly or maliciously constructed archive can extract a file into any user-writable location on the system using relative pathnames. This issue is addressed in container 0.8.0 and containerization 0.21.0.

7.8 CVSS 3.1 High EPSS 0.28% · top 82.0% CWE-22 · Path traversal
7.8CVSS 3.1 base score
0.28%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
1References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

The ArchiveReader.extractContents() function used by cctl image load and container image load performs no pathname validation before extracting an archive member. This means that a carelessly or maliciously constructed archive can extract a file into any user-writable location on the system using relative pathnames. This issue is addressed in container 0.8.0 and containerization 0.21.0.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-20613 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2026-64773Apple container allocation without limits vulnerabilityAn attacker that can reach a container's published TCP port may be able to force the host's forwarding process to buffer an unbounded amount of that …EPSS 0.43%6.5CVE-2026-28909Apple container insufficiently protected credentials vulnerabilityUsers who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentials exposed in plaintext. This…EPSS 0.32%4.3CVE-2026-64777Apple container path traversal vulnerabilityA malicious builder peer may be able to request an in-context file by name from the host and receive the contents of whatever the name resolves to, e…EPSS 0.34%9.8CVE-2026-93616Checkpoint multi-domain security management path traversal vulnerabilityA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Managem…KEVEPSS 20%10.0CVE-2026-85706GitLab CE/EE repository commits API path traversal allows unauthenticated file readGitLab CE/EE contains improper path confinement and missing authentication enforcement in the repository commits API, allowing an unauthenticated use…KEVEPSS 91%analysed5.3CVE-2026-66384JFrog Artifactory path traversal in Docker cache pathAn authenticated user can write data outside the intended Docker cache path under specific remote-repository conditions in JFrog Artifactory. The fla…KEVEPSS 0.66%analysed9.8CVE-2026-59310VMware vCenter Syslog server path traversal leads to RCEVMware vCenter's Syslog server is affected by a directory traversal flaw (CWE-22) that allows a remote, unauthenticated attacker to execute arbitrary…KEVEPSS 2.6%analysed10.0CVE-2026-48282Adobe ColdFusion path traversal leads to remote code executionColdFusion versions 2025.9, 2023.20 and earlier contain a path traversal flaw (CWE-22) that allows an unauthenticated remote attacker to reach files …KEVEPSS 42%analysed

Source: NIST National Vulnerability Database (record CVE-2026-20613), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.