CVE-2026-25143 | chainguard-dev melange up to 0.40.2 Configuration patch.yaml os command injection (GHSA-rf4g-89h5-crcr)
A vulnerability described as critical has been identified in chainguard-dev melange up to 0.40.2. This affects an unknown part of the file pkg/build/pipelines/patch.yaml of the component Configuration Handler. The manipulation results in os command injection.
This vulnerability is reported as CVE-2026-25143. The attack requires a local approach. No exploit exists.
Upgrading the affected component is recommended.