{"id":"CVE-2026-20613","details":"The ArchiveReader.extractContents() function used by cctl image load and container image load performs no pathname validation before extracting an archive member. This means that a carelessly or maliciously constructed archive can extract a file into any user-writable location on the system using relative pathnames. This issue is addressed in container 0.8.0 and containerization 0.21.0.","aliases":["GHSA-cq3j-qj2h-6rv3"],"modified":"2026-07-15T06:21:54.843686Z","published":"2026-01-23T00:15:52.283Z","references":[{"type":"EVIDENCE","url":"https://github.com/apple/containerization/security/advisories/GHSA-cq3j-qj2h-6rv3"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apple/container","events":[{"introduced":"0"},{"fixed":"a18df81eb0a7fa5e77c76e38fb3b3424846e3690"}],"database_specific":{"cpe":"cpe:2.3:a:apple:container:*:*:*:*:*:swift:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.8.0"}],"source":"CPE_RANGE"}}],"versions":["0.7.1","0.7.0","0.6.0","0.5.0","0.4.1","0.4.0","0.3.0","0.2.0","0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-20613.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/apple/containerization","events":[{"introduced":"0"},{"fixed":"51ef9f81fef574bbd815d4f5560157297b0a4067"},{"fixed":"f570b8734ebd11727655bc68d4597bda1656365e"}],"database_specific":{"cpe":["cpe:2.3:a:apple:container:*:*:*:*:*:swift:*:*","cpe:2.3:a:apple:containerization:*:*:*:*:*:swift:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"0.8.0"},{"fixed":"0.21.0"}],"source":"CPE_RANGE"}}],"versions":["0.20.1","0.20.0","0.19.0","0.18.0","0.17.1","0.17.0","0.16.2","0.16.1","0.16.0","0.15.1","0.15.0","0.14.0","0.13.0","0.12.1","0.12.0","0.11.0","0.10.1","0.10.0","0.9.1","0.9.0","0.8.1","0.8.0","0.7.2","0.7.1","0.7.0","0.6.2","0.6.1","0.6.0","0.5.0","0.4.1","0.4.0","0.3.0","0.2.0","0.1.1","0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-20613.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}