CVE-2026-29050 | chainguard-dev melange up to 0.43.3 Configuration File filepath.Join pipeline[] path traversal (GHSA-98f2-w9h9-7fp9)
A vulnerability labeled as critical has been found in chainguard-dev melange up to 0.43.3. This impacts the function filepath.Join of the component Configuration File Handler. Executing a manipulation of the argument pipeline[] can lead to path traversal.
This vulnerability is handled as CVE-2026-29050. It is possible to launch the attack on the local host. There is not any exploit available.
The affected component should be upgraded.