Vulnerabilities
Report: Update: CVE-2026-29050 - melange has Path Traversal When Resolving External Pipelines via Unvalidated pip...
CVE ID :CVE-2026-29050 Published : April 24, 2026, 12:16 a.m. | 1 hour, 31 minutes ago Description :melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version 0.43.4, an attacker who can influence a melange configuration file — for example through pull-request-driven CI or build-as-a-service scenarios — could set `pipeline[].uses` to a value containing `../` sequences or an absolute path. The `(*Compiled).compilePipeline` function in `pkg/build/compile.go` passed `uses` directly to `filepath.Join(pipelineDir, uses +
CVE Details
CVE ID
Published
April 24, 2026