To report a security issue with Kaniko, please use https://g.co/vulnz. We use https://g.co/vulnz for our intake, and do coordination and disclosure here on GitHub (including using GitHub Security Advisory). The Google Security Team will respond within 5 working days of your report on g.co/vulnz.
Security: chainguard-forks/kaniko
Security
SECURITY.md
-
tar archive path traversal in build context extraction allows writing files outside destination directoryGHSA-6rxq-q92g-4rmf published
Feb 27, 2026 by egibsHigh
Learn more about advisories related to chainguard-forks/kaniko in the GitHub Advisory Database