A high-severity flaw tracked as CVE-2026-54574 affects Termux proot-distro versions earlier than 5.1.5, allowing a malicious archive to escape the intended extraction directory and write files to arbitrary locations on the host filesystem. The bug lies in proot-distro's handling of plain tarball root filesystems and Docker layers during operations such as proot-distro install and proot-distro restore, where archive-controlled symbolic links were not safely validated before subsequent files were extracted through them.
The vulnerability arises because lexical path traversal checks did not account for filesystem state changes after a symlink was created, enabling an attacker to craft an archive that first creates a symlink to an absolute host path and then writes a later file through that link. Reported impact includes possible writes to sensitive files such as /etc/shadow or files in a Termux home directory, with the issue classified as CWE-61 and scored CVSS 7.1 (AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N). The issue was fixed in proot-distro 5.1.5, including a safer extraction approach using _safe_resolve() in proot_distro/helpers/tar_extract.py.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
The symlink escape and arbitrary host file write vulnerability affecting proot-distro versions earlier than 5.1.5 was fixed in release 5.1.5. The flaw involved unsafe handling of archive-controlled symlinks during tar extraction, enabling writes to host filesystem paths via malicious archives.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvereports.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.