GHSA-2w4f-9fgg-q2v9
melange has a path traversal in license-path which allows reading files outside workspace
Quick fix
GHSA-2w4f-9fgg-q2v9 — chainguard.dev/melange: upgrade to the fixed version with the command below.
go get chainguard.dev/melange@v0.40.3Details
An attacker who can influence a melange configuration file (e.g., through pull request-driven CI or build-as-a-service scenarios) could read arbitrary files from the host system. The `LicensingInfos` function in `pkg/config/config.go` reads license files specified in `copyright[].license-path` without validating that paths remain within the workspace directory, allowing path traversal via `../` sequences. The contents of the traversed file are embedded into the generated SBOM as license text, enabling exfiltration of sensitive data through build artifacts. Fix: Merged in commit 2f95c9f4 Acknowledgements melange thanks Oleh Konko (@1seal) from 1seal for discovering and reporting this issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
0.14.0Fixed in: 0.40.3go get chainguard.dev/melange@v0.40.3