<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T16:07:26.672796+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-326608</id>
    <title>EUVD-2026-326608</title>
    <updated>2026-10-08T16:07:26.776659+00:00</updated>
    <content>EUVD-2026-326608</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-326608"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46703</id>
    <title>fkie_cve-2026-46703</title>
    <updated>2026-10-08T16:07:26.776713+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version 0.9.0, Boxlite allows users to specify the OCI image used by containers in the sandbox. However, when processing tar entries in OCI images, Boxlite does not account for the possibility that entries may be symlinks pointing to absolute paths. An attacker can craft a malicious OCI image and distribute it on image hosting platforms such as DockerHub, tricking users into using it. Once a user loads the malicious image, the attacker can write arbitrary content to any path on the host, which can further lead to remote code execution on the host. This issue has been patched in version 0.9.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-46703"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-f396-4rp4-7v2j</id>
    <title>GHSA-f396-4rp4-7v2j — Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the Host</title>
    <updated>2026-10-08T16:07:26.776774+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: boxlite, crates.io: boxlite-cli, crates.io: boxlite, npm: @boxlite-ai/boxlite, Go: github.com/boxlite-ai/boxlite/sdks/go</p>
<p>#### Summary</p>
<p>Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and run OCI containers within them. Boxlite allows users to specify the OCI image used by containers in the sandbox. However, when processing tar entries in OCI images, Boxlite does not account for the possibility that entries may be symlinks pointing to absolute paths. An attacker can craft a malicious OCI image and distribute it on image hosting platforms such as DockerHub, tricking users into using it. Once a user loads the malicious image, the attacker can write arbitrary content to any path on the host, which can further lead to remote code execution on the host.</p>
<p>#### Details</p>
<p>1. Entry Point — OCI Layer Tarball Extraction</p>
<p>**File:** `boxlite/src/images/archive/tar.rs` **Function:** `extract_layer_tarball_streaming()` (line 24) **Code:**</p>
<p>```rust
pub fn extract_layer_tarball_streaming(tarball_path: &amp;Path, dest: &amp;Path) -&gt; BoxliteResult&lt;u64&gt; {
    // ...
    apply_oci_layer(reader, dest)
}
```</p>
<p>**Issue:** The function passes the tar reader into `apply_oci_layer`. The tarball comes from a registry blob that has passed SHA256 integrity verification against the manifest digest — but the manifest itself is controlled by the registry, so a malicious registry can serve a valid manifest pointing to a crafted layer blob with a matching digest.</p>
<p>2. Main Extraction Loop — Symlink Created Without Target Validation</p>
<p>**File:** `boxlite/src/images/archive/tar.rs` **Function:**…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-f396-4rp4-7v2j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-298</id>
    <title>PYSEC-2026-298 — Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the Host</title>
    <updated>2026-10-08T16:07:26.777033+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: boxlite</p>
<p>#### Summary</p>
<p>Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and run OCI containers within them. Boxlite allows users to specify the OCI image used by containers in the sandbox. However, when processing tar entries in OCI images, Boxlite does not account for the possibility that entries may be symlinks pointing to absolute paths. An attacker can craft a malicious OCI image and distribute it on image hosting platforms such as DockerHub, tricking users into using it. Once a user loads the malicious image, the attacker can write arbitrary content to any path on the host, which can further lead to remote code execution on the host.</p>
<p>#### Details</p>
<p>1. Entry Point — OCI Layer Tarball Extraction</p>
<p>**File:** `boxlite/src/images/archive/tar.rs` **Function:** `extract_layer_tarball_streaming()` (line 24) **Code:**</p>
<p>```rust
pub fn extract_layer_tarball_streaming(tarball_path: &amp;Path, dest: &amp;Path) -&gt; BoxliteResult&lt;u64&gt; {
    // ...
    apply_oci_layer(reader, dest)
}
```</p>
<p>**Issue:** The function passes the tar reader into `apply_oci_layer`. The tarball comes from a registry blob that has passed SHA256 integrity verification against the manifest digest — but the manifest itself is controlled by the registry, so a malicious registry can serve a valid manifest pointing to a crafted layer blob with a matching digest.</p>
<p>2. Main Extraction Loop — Symlink Created Without Target Validation</p>
<p>**File:** `boxlite/src/images/archive/tar.rs` **Function:**…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-298"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rustsec-2026-0148</id>
    <title>RUSTSEC-2026-0148 — OCI layer symlink escape → arbitrary host write</title>
    <updated>2026-10-08T16:07:26.777285+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: boxlite</p>
<p>Affected versions of `boxlite` extract OCI image layer tarballs without
fully containing path resolution to the extraction root. A crafted layer
containing a symlink whose target is an absolute on-host path (e.g.
`escape -&gt; /tmp`) followed by a file entry that resolves through that
symlink (e.g. `escape/&lt;path&gt;/pwned.txt`) caused the extractor to write
the payload to the host filesystem outside the intended rootfs directory.</p>
<p>The fix in v0.9.0 routes every destructive filesystem operation through a
`SafeRoot` handle (`openat2(RESOLVE_IN_ROOT)` on Linux, lexical fallback
elsewhere) so that no tar entry can resolve outside the extraction root,
even with adversarial symlinks placed by earlier entries in the same
layer.</p>
<p>This is a container-escape during image extraction, exploitable by any
user who pulls or loads a malicious OCI image — including via
`SimpleBox(rootfs_path=...)` from an untrusted local layout.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rustsec-2026-0148"/>
  </entry>
</feed>
