Back

HIGH

Oc-mirror: oc-mirror: path traversal / arbitrary file write in operator catalog image extraction

Published Sep 30, 2026

Description

Path traversal / arbitrary file write in oc-mirror's operator catalog image extraction. When mirroring operator catalogs using either the legacy v1 path (--v1) or the OCI feature path (--use-oci-feature), oc-mirror extracts tar entries from catalog image layers without validating that file paths resolve within the intended destination directory.

Affected products

Remediation

Red Hat statement

A path traversal vulnerability was found in oc-mirror's operator catalog image extraction. When mirroring operator catalogs using either the legacy v1 path (--v1) or the OCI feature path (--use-oci-feature), oc-mirror extracts tar entries from catalog image layers without validating that file paths resolve within the intended destination directory. A malicious or compromised operator catalog image could exploit this to write arbitrary files on the administrator's workstation with the privileges of the oc-mirror process.

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 30, 2026
Updated Sep 30, 2026
Reserved Sep 28, 2026
CISA Vulnrichment
Updated Sep 30, 2026
NVD
Status Received
Modified Sep 30, 2026
Red Hat
Severity Moderate
Public date Sep 30, 2026
ENISA EUVD
Assigner redhat
Published Sep 30, 2026
Updated Sep 30, 2026
Exploited since n/a
EUVD-2026-89959