Path traversal / arbitrary file write in oc-mirror's operator catalog image extraction. When mirroring operator catalogs using either the legacy v1 path (--v1) or the OCI feature path (--use-oci-feature), oc-mirror extracts tar entries from catalog image layers without validating that file paths resolve within the intended destination directory.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 30 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Path traversal / arbitrary file write in oc-mirror's operator catalog image extraction. When mirroring operator catalogs using either the legacy v1 path (--v1) or the OCI feature path (--use-oci-feature), oc-mirror extracts tar entries from catalog image layers without validating that file paths resolve within the intended destination directory. | |
| Title | Oc-mirror: oc-mirror: path traversal / arbitrary file write in operator catalog image extraction | |
| First Time appeared |
Redhat
Redhat assisted Installer Redhat openshift |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:/a:redhat:assisted_installer:2 cpe:/a:redhat:openshift:4 |
|
| Vendors & Products |
Redhat
Redhat assisted Installer Redhat openshift |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-30T14:06:16.437Z
Reserved: 2026-09-28T13:01:18.667Z
Link: CVE-2026-101295
No data.
Status : Received
Published: 2026-09-30T15:22:19.423
Modified: 2026-09-30T15:22:19.423
Link: CVE-2026-101295
No data.
OpenCVE Enrichment
No data.
Weaknesses