---
id: CVE-2026-107174
title: A flaw was found in source-to-image
summary: >-
  A flaw was found in source-to-image. When unpacking archive files, the
  application fails to properly sanitize symbolic links pointing to absolute
  file paths. An attacker who supplies a malicious builder image can exploit
  this vulnerabili…
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-61
vendor: Red Hat
product: openshift-serverless-1/kn-client-kn-rhel9
affected:
  - openshift-serverless-1/kn-client-kn-rhel9 (all versions)
  - openshift-serverless-1/kn-plugin-func-func-util-rhel9 (all versions)
  - openshift-serverless-clients (all versions)
  - source-to-image/source-to-image-rhel8 (all versions)
  - source-to-image/source-to-image-rhel9 (all versions)
  - openshift4/ose-docker-builder (all versions)
  - openshift4/ose-docker-builder-rhel9 (all versions)
  - web-terminal/web-terminal-tooling-rhel9 (all versions)
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T17:16:53.380'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107174'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2026-107174'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2547419'
    label: secalert@redhat.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-07T16:17:10.638072Z'
ingestedAt: '2026-10-07T15:36:04.055Z'
---

## Overview

A flaw was found in source-to-image. When unpacking archive files, the application fails to properly sanitize symbolic links pointing to absolute file paths. An attacker who supplies a malicious builder image can exploit this vulnerability by embedding links pointing outside the extraction directory. This allows the attacker to bypass sandbox boundaries, potentially leading to unauthorized information disclosure or file modification on the host system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
