Oc-mirror: oc-mirror: path traversal / arbitrary file write in operator catalog image extraction
Published Sep 30, 2026
7.3
HIGHCVSS 3.1
EPSS 0.14%
Description
Path traversal / arbitrary file write in oc-mirror's operator catalog image extraction. When mirroring operator catalogs using either the legacy v1 path (--v1) or the OCI feature path (--use-oci-feature), oc-mirror extracts tar entries from catalog image layers without validating that file paths resolve within the intended destination directory.
Affected products
No data.
No data.
No data.
Assisted Installer for Red Hat OpenShift Container Platform 2
assisted/agent-preinstall-image-builder-rhel9
Under investigation
Red Hat OpenShift Container Platform 4
openshift4/oc-mirror-plugin-rhel8
Under investigation
Red Hat OpenShift Container Platform 4
openshift4/oc-mirror-plugin-rhel9
Under investigation
| Product | Package | State | Advisory |
|---|---|---|---|
| Assisted Installer for Red Hat OpenShift Container Platform 2 | assisted/agent-preinstall-image-builder-rhel9 | Under investigation | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/oc-mirror-plugin-rhel8 | Under investigation | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/oc-mirror-plugin-rhel9 | Under investigation | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
A path traversal vulnerability was found in oc-mirror's operator catalog image extraction. When mirroring operator catalogs using either the legacy v1 path (--v1) or the OCI feature path (--use-oci-feature), oc-mirror extracts tar entries from catalog image layers without validating that file paths resolve within the intended destination directory. A malicious or compromised operator catalog image could exploit this to write arbitrary files on the administrator's workstation with the privileges of the oc-mirror process.
References (7)
- https://access.redhat.com/security/cve/CVE-2026-101295 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2522941 issue-trackingx_refsource_REDHATIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-89959 Advisory
- https://github.com/openshift/oc-mirror/blob/22a5722/v1/pkg/cli/mirror/catalog_images.go#L680
- https://github.com/openshift/oc-mirror/blob/22a5722/v1/pkg/cli/mirror/fbc_operators.go#L334-L369
- https://nvd.nist.gov/vuln/detail/CVE-2026-101295
- https://www.cve.org/CVERecord?id=CVE-2026-101295
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-101295 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2522941 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-89959 | Advisory | |
| https://github.com/openshift/oc-mirror/blob/22a5722/v1/pkg/cli/mirror/catalog_images.go#L680 | ||
| https://github.com/openshift/oc-mirror/blob/22a5722/v1/pkg/cli/mirror/fbc_operators.go#L334-L369 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2026-101295 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-101295 |
Change history (0)
No recorded changes yet.