GHSA-46jg-fhwv-c6jpMediumCVSS 6.9

MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package...

Published
September 14, 2026
Last Modified
September 16, 2026

🔗 CVE IDs covered (1)

📋 Description

MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container root by supplying a crafted container image with symlinks pointing to arbitrary paths. Attackers can exploit unsanitized tar member path extraction during container import via /container/add to achieve root-privileged file creation, directory creation, file deletion via overlayfs whiteout, and hardlink creation on the persistent data partition without ever starting the container. The 7.23.x long-term branch does not contain this fix; the container binaries in container-7.23.3.npk and container-7.23.4.npk are byte-identical, and there is no fixed long-term release at the time of publication.

🔗 References (5)