CVE-2026-45384: Insecure Symlink Resolution Basepath
A symlink target is constructed and validated against an extraction base path instead of the symlink's actual parent directory. This writes absolute or structurally vulnerable relative paths directly into the symlink, leading to path traversal bypasses when traversed by the OS. Derive the safe execution target using `lexically_relative(symlink.parent_path())
greprules fetch cve-2026-45384-insecure-symlink-resolution-basepath --engine opengrepDescription
A symlink target is constructed and validated against an extraction base path instead of the symlink's actual parent directory. This writes absolute or structurally vulnerable relative paths directly into the symlink, leading to path traversal bypasses when traversed by the OS. Derive the safe execution target using `lexically_relative(symlink.parent_path())
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.