Security: Containerpak/cpak
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
A package can write a desktop entry with an arbitrary name and content, including the user's default handler databaseGHSA-j6xr-vfgf-crjj published
Aug 19, 2026 by mirkobrombinHigh -
The installation consent prompt prints unfiltered publisher text and can be overdrawn with terminal escapesGHSA-8xvc-2crm-896j published
Aug 19, 2026 by mirkobrombinHigh -
Dependency permissions are never shown at install time and dependencies run under their own policyGHSA-vgmh-f9c4-xw9w published
Aug 19, 2026 by mirkobrombinHigh -
The nested-run socket uses a fixed name in a shared temporary directory with no owner checkGHSA-v969-ggc3-x8vx published
Aug 19, 2026 by mirkobrombinHigh -
The application sandbox fails open when Landlock is unavailableGHSA-j4rq-qh5p-f8j6 published
Aug 19, 2026 by mirkobrombinHigh -
Version 1 manifests bypass the state mask and the private homeGHSA-76p3-2jhf-6hq3 published
Aug 19, 2026 by mirkobrombinHigh -
The cpak state mask does not apply to host-scope or in-tree grants, exposing other containers' broker tokensGHSA-qgv3-4h87-pghg published
Aug 19, 2026 by mirkobrombinHigh -
The file-grant worker retains a pre-pivot root, exposing the whole host filesystem to applications running as root in the containerGHSA-ffr9-fhr4-gjfp published
Aug 19, 2026 by mirkobrombinCritical -
The nested-run socket accepts the caller's claimed parent identity, allowing a package to run under another application's permissionsGHSA-849w-qv8v-wqm5 published
Aug 19, 2026 by mirkobrombinCritical -
Trust markers in an exported desktop entry can be smuggled by the publisher, granting read access to any pathGHSA-f4mc-3pfx-5gqv published
Aug 19, 2026 by mirkobrombinCritical
Learn more about advisories related to Containerpak/cpak in the GitHub Advisory Database