CVE-2026-24846 | chainguard-dev malcontent up to 1.20.2 Tar handleSymlink path traversal (GHSA-923j-vrcg-hxwh / EUVD-2026-4947)
A vulnerability described as critical has been identified in chainguard-dev malcontent up to 1.20.2. This issue affects the function handleSymlink of the component Tar Handler. The manipulation results in path traversal.
This vulnerability is identified as CVE-2026-24846. The attack is only possible with local access. There is not any exploit available.
Upgrading the affected component is recommended.