
CVE-2026-29051: CVE-2026-29051: Path Traversal in Melange via Unvalidated .PKGINFO Fields Melange versions prior to 0.43.4 are vulnerable to a path traversal attack when processing untrusted APK packages with the `--persist-lint-results` flag. Attacke... https://cvereports.com/reports/CVE-2026-29051
Post summary
CVE‑2026‑29051 is a path traversal vulnerability in Melange version prior to 0.43.4 that occurs when untrusted APK packages are processed with the `--persist-lint-results` flag; no PoC, exploit tool, active exploitation evidence, or patch details are presented.


