Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3607
  • PyPI/proot-distro
proot-distro has a Container Isolation Bypass via Crafted Restore Archive 04 Aug
  • Fix available
  • Severity - 8.2 (High)
PYSEC-2026-3608
  • PyPI/proot-distro
`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive 04 Aug
  • Fix available
  • Severity - 8.2 (High)
GHSA-7h3g-4w2f-fj2f
  • PyPI/proot-distro
proot-distro has a Container Isolation Bypass via Crafted Restore Archive 29 Jul
  • Fix available
  • Severity - 8.2 (High)
GHSA-9xq3-3fqg-4vg7
  • PyPI/proot-distro
`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive 29 Jul
  • Fix available
  • Severity - 8.2 (High)
GHSA-mfr4-mq8w-vmg6
  • PyPI/proot-distro
PRoot-Distro has Path Traversal in proot-distro copy — Arbitrary Read, Write, and Persistent Code Execution Outside Container Rootfs 17 Jul
  • Fix available
  • Severity - 6.6 (Medium)