UNIX Symbolic Link (Symlink) Following Affecting proot-distro package, versions [,5.1.5)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.14% (5th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-PROOTDISTRO-18507997
  • published2 Aug 2026
  • disclosed29 Jul 2026
  • creditUnknown

Introduced: 29 Jul 2026

NewCVE-2026-54574  (opens in a new tab)
CWE-61  (opens in a new tab)

How to fix?

Upgrade proot-distro to version 5.1.5 or higher.

Overview

proot-distro is a PRoot-Distro is a lightweight rootless Linux container management utility built around proot.

Affected versions of this package are vulnerable to UNIX Symbolic Link (Symlink) Following in the proot_distro/commands/install.py function and the equivalent process in helpers/docker.py when extracting a tar archive containing a symlink whose target is an absolute host path. An attacker can overwrite arbitrary files on the host system with the privileges of the Termux process by supplying a malicious tar archive containing such a symlink and a subsequent file entry that traverses through it.

CVSS Base Scores

version 4.0
version 3.1