Affected by GO-2026-4391
and 1 other vulnerabilities
GO-2026-4391: malcontent vulnerable to symlink Path Traversal via handleSymlink argument confusion in archive extraction in github.com/chainguard-dev/malcontent
GO-2026-4392: malcontent OCI image pull credential exfiltration via malicious registry token realm in github.com/chainguard-dev/malcontent