A AegiFlow
HIGHCVSS 8.2EPSS 0.1%

CVE-2026-54727

CVE-2026-54727 updated by NVD

Published
2026-07-29
Modified
2026-07-31
EPSS percentile
2%
Sources
github-advisory, nvd

Summary

proot-distro is a utility for managing proot containers. Prior to version 5.1.6, proot-distro restore accepted hardlink entries whose linkname referenced another installed container and did not verify that the hardlink source container matched the destination container being restored, allowing a crafted restore archive to copy files between otherwise isolated containers. This issue is fixed in version 5.1.6.

Affected packages

EcosystemPackageAffected versionsFixed versions
PyPIproot-distro5.1.6

Remediation: Upgrade to 5.1.6 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.