Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/google/osv-scalibr/pull/2030 |
|
Tue, 29 Sep 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A path traversal vulnerability (CWE-22) in the embedded VMDK filesystem extractor in Google OSV-SCALIBR versions 0.3.6 through 0.5.0 allows an attacker who controls the scan target to write arbitrary files to the host system. When scanning crafted VMDK images, insufficient validation of archive path entries allows file extractions to escape destination directories. | |
| Title | Path Traversal in VMDK Extractor in OSV-SCALIBR | |
| Weaknesses | CWE-22 CWE-23 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Google
Published:
Updated: 2026-09-29T19:41:42.440Z
Reserved: 2026-09-28T19:17:24.232Z
Link: CVE-2026-102252
No data.
Status : Received
Published: 2026-09-29T20:17:11.910
Modified: 2026-09-29T20:17:11.910
Link: CVE-2026-102252
No data.
OpenCVE Enrichment
No data.