Answer in brief
CVE-2026-55569 records a Medium severity (CVSS 6.6) vulnerability in Aqua's archive extraction follows attacker-planted symlinks, allowing writes outside the install directory. The current sources do not mark it as known exploited. The current feed maps github.com/aquaproj/aqua/v2 (go). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 6.6. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps github.com/aquaproj/aqua/v2 (go). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| github.com/aquaproj/aqua/v2go | <2.60.1 | 2.60.1 |
Published upstream
Aug 28, 2026
Evidence: source:ghsa:source_dates:source-dates:recordSource modified
Aug 28, 2026
Evidence: source:ghsa:source_dates:source-dates:recordFirst seen by HOL
Aug 28, 2026
### Summary `aquaproj/aqua` extracts downloaded tool archives through `pkg/unarchive/archives.go` using `github.com/mholt/archives`. The archive handler creates symlink entries with `os.Symlink(f.LinkTarget, dstPath)` without validating that the symlink target resolves inside the extraction destination. A subsequent regular-file archive entry with the same path is opened with `OpenFile(dstPath, O_CREATE|O_WRONLY)`, which follows the attacker-planted symlink. A malicious or compromised aqua package / release asset can therefore write attacker-controlled bytes outside aqua's extraction directory, with the privileges of the user running aqua. ### Details Affected file: `pkg/unarchive/archives.go` Affected function: `(*handler).HandleFile` The vulnerable logic is the combination of: ```go os.Symlink(f.LinkTarget, dstPath) ``` for symlink entries, followed by: ```go h.fs.OpenFile(dstPath, os.O_CREATE|os.O_WRONLY, f.Mode()) ``` for a later regular file entry at the same archive path. The symlink target is not jailed to the extraction destination, and the later file open follows the symlink. The attached PoC uses a two-entry `tar.gz` archive: 1. symlink `pwn -> <outside target>`; 2. regular file `pwn` containing attacker-controlled bytes. The same `mholt/archives` extraction flow is used for the vulnerable handler and for a negative-control handler using a destination-root jail. ### PoC Attachment: `submission_aqua_archive_symlink_traversal_v2_final.zip` Run: ```bash go run mkarchive.go /tmp/aqua-outside-target go build -o aqua-archive-poc . mkdir -p /tmp/aqua-dest ./aqua-archive-poc vuln /tmp/aqua-dest malicious.tar.gz cat /tmp/aqua-outside-target mkdir -p /tmp/aqua-dest-safe ./aqua-archive-poc safe /tmp/aqua-dest-safe malicious.tar.gz ``` Expected vulnerable result: ```text /tmp/aqua-outside-target contains PWNED_BY_AQUA_SYMLINK_TRAVERSAL ``` Expected safe-control result: ```text The escaping symlink / write is rejected and the outside target is unchanged. ``` ### Impact An attacker who controls an archive that aqua installs can write attacker-controlled content to paths outside the extraction destination, limited by the filesystem permissions of the user running aqua. This can lead to user-level code execution if the overwritten path is later executed or interpreted, for example a shell startup file, a tool configuration file, or a writable PATH entry. This report does not claim privilege escalation beyond the aqua process privileges.
Quoted source text, attributed separately from HOL analysis.