proot-distro vulnerabilities
CVEs whose affected-version data names the proot-distro package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-54574High· 8.2`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive
`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive
▾ Twilightproot-distro · proot-distroEPSS 0.14%via GHSA
CVE-2026-54727High· 8.2proot-distro has a Container Isolation Bypass via Crafted Restore Archive
proot-distro has a Container Isolation Bypass via Crafted Restore Archive
▾ Twilightproot-distro · proot-distroEPSS 0.12%via GHSA
GHSA-mfr4-mq8w-vmg6Medium· 6.6PRoot-Distro has Path Traversal in proot-distro copy — Arbitrary Read, Write, and Persistent Code Execution Outside Container Rootfs
PRoot-Distro has Path Traversal in proot-distro copy — Arbitrary Read, Write, and Persistent Code Execution Outside Container Rootfs
▾ Sunlitproot-distro · proot-distrovia GHSA