Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. proot-distro
  4. ›
  5. CVE-2026-54727

CVE-2026-54727: proot-distro has a Container Isolation Bypass via Crafted Restore Archive

July 29, 2026

When restoring a crafted backup archive, proot-distro restore accepts hardlink entries whose source path references a different installed container.

The restore logic resolves the hardlink source from the archive’s linkname field and copies the referenced file into the container identified by the archive entry.

Although path traversal protections correctly keep the source path inside the proot-distro containers directory, no validation ensures that the hardlink source container matches the destination container.

As a result, a malicious backup archive can copy files between otherwise isolated containers, enabling both cross-container disclosure and cross-container file injection.


References

  • github.com/advisories/GHSA-7h3g-4w2f-fj2f
  • github.com/termux/proot-distro/commit/98aff324b7d8500ff75a8ca9ac087ee636be4716
  • github.com/termux/proot-distro/releases/tag/v5.1.6
  • github.com/termux/proot-distro/security/advisories/GHSA-7h3g-4w2f-fj2f
  • nvd.nist.gov/vuln/detail/CVE-2026-54727

Code Behaviors & Features

Detect and mitigate CVE-2026-54727 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 5.1.6

Fixed versions

  • 5.1.6

Solution

Upgrade to version 5.1.6 or above.

Impact 8.2 HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Learn more about CVSS

Weakness

  • CWE-668: Exposure of Resource to Wrong Sphere

Source file

pypi/proot-distro/CVE-2026-54727.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 08 Aug 2026 00:17:17 +0000.