« Volver al listado

CVE-2026-20613

Estado: AnalizadaAlta (7.8)—

The ArchiveReader.extractContents() function used by cctl image load and container image load performs no pathname validation before extracting an archive member. This means that a carelessly or maliciously constructed archive can extract a file into any user-writable location on the system using relative pathnames. This issue is addressed in container 0.8.0 and containerization 0.21.0.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Requiere interacción del usuario (UI:R) para abrir un archivo malicioso comprimido: T1203. La vulnerabilidad CWE-22 permite escribir en cualquier ubicación accesible (impacto de manipulación de datos T1565.001, con potencial ejecución posterior T1059).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-20613",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-20613",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-01-23T14:56:08.027445Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "product-security@apple.com",
      "affectedData": [
        {
          "vendor": "Apple",
          "product": "Container",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "0.7.1",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Apple",
          "product": "Containerization",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "0.20.1",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-01-23T00:15:52.283",
  "references": [
    {
      "url": "https://github.com/apple/containerization/security/advisories/GHSA-cq3j-qj2h-6rv3",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "product-security@apple.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The ArchiveReader.extractContents() function used by cctl image load and container image load performs no pathname validation before extracting an archive member. This means that a carelessly or maliciously constructed archive can extract a file into any user-writable location on the system using relative pathnames. This issue is addressed in container 0.8.0 and containerization 0.21.0."
    },
    {
      "lang": "es",
      "value": "La función ArchiveReader.extractContents() utilizada por cctl image load y contenedor image load no realiza ninguna validación de rutas antes de extraer un miembro del archivo. Esto significa que un archivo construido de forma descuidada o maliciosa puede extraer un archivo en cualquier ubicación escribible por el usuario en el sistema utilizando rutas relativas. Este problema se aborda en contenedor 0.8.0 y containerization 0.21.0."
    }
  ],
  "lastModified": "2026-06-17T10:17:31.753",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apple:container:*:*:*:*:*:swift:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C6FA03D6-D8FD-484D-ABC3-C4E06F004E9B",
              "versionEndExcluding": "0.8.0"
            },
            {
              "criteria": "cpe:2.3:a:apple:containerization:*:*:*:*:*:swift:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1FE4C5FD-62B9-4CCC-90EA-065CDF156FFD",
              "versionEndExcluding": "0.21.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "product-security@apple.com"
}