CVE-2026-101295 PUBLISHED

Oc-mirror: oc-mirror: path traversal / arbitrary file write in operator catalog image extraction

Assigner: redhat
Reserved: 28.09.2026 Published: 30.09.2026 Updated: 30.09.2026

Path traversal / arbitrary file write in oc-mirror's operator catalog image extraction. When mirroring operator catalogs using either the legacy v1 path (--v1) or the OCI feature path (--use-oci-feature), oc-mirror extracts tar entries from catalog image layers without validating that file paths resolve within the intended destination directory.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
CVSS Score: 7.3

Product Status

Vendor Red Hat
Product Assisted Installer for Red Hat OpenShift Container Platform 2
Versions Default: unknown
Vendor Red Hat
Product Red Hat OpenShift Container Platform 4
Versions Default: unknown
Vendor Red Hat
Product Red Hat OpenShift Container Platform 4
Versions Default: unknown

References

Problem Types

  • Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE