CVE-2026-28406 is a high-severity path traversal vulnerability (CVSS 8.2) affecting kaniko versions 1.25.4 through 1.25.9, including Chainguard kaniko. This flaw allows an attacker to write files outside the intended destination directory during container image builds by crafting malicious tar archives. With a network attack vector and low attack complexity, an unauthenticated attacker can exploit this without user interaction, leading to high integrity impact and potential code execution when chained with Docker credential helpers in registry-authenticated environments. While the vulnerability has a high CVSS score, there is currently no evidence of active exploitation, nor are public exploit tools available, and community discussion remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.25.4, < 1.25.10CPE matchmatch criteria | cpe:2.3:a:chainguard:kaniko:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.