CVE-2026-44933
EUVD-2026-3107420.05.2026, 10:16
`PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot`, this root is frequently `/` (the system root) in standard configurations or when using `--root`. If the chroot target is `/`, it is a no-op, allowing the traversed path to execute host binaries (like `/bin/bash`) with root privileges.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.