proot-distro
PyPI2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting proot-distropage 1 of 1
- CVE-2026-54574HIGHCVSS 8.2EG 8.2✓ Fixed in 5.1.52026-07-29
vulnerable: 5.0.0 ... 5.1.4 (13 versions)
proot-distro is a utility for managing proot containers. Prior to version 5.1.5, proot-distro install extracted plain tarball root filesystems through _extract_plain_tar() in proot_distro/commands/install.py and Docker layers through _appl…
- CVE-2026-54727HIGHCVSS 8.2EG 8.2✓ Fixed in 5.1.62026-07-29
vulnerable: 5.0.0 ... 5.1.5 (14 versions)
proot-distro is a utility for managing proot containers. Prior to version 5.1.6, proot-distro restore accepted hardlink entries whose linkname referenced another installed container and did not verify that the hardlink source container mat…
Check whether proot-distro is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for proot-distro CVEs against the assets you own.
Start Free Scan →