Description
Path traversal / arbitrary file write in oc-mirror's operator catalog image extraction. When mirroring operator catalogs using either the legacy v1 path (--v1) or the OCI feature path (--use-oci-feature), oc-mirror extracts tar entries from catalog image layers without validating that file paths resolve within the intended destination directory.
Published: 2026-09-30
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: Arbitrary File Write
Action: Immediate Patch
AI Analysis

Impact

The vulnerability permits an attacker to write arbitrary files during the extraction of operator catalog images performed by oc‑mirror. By exploiting a path traversal flaw, the tool saves tar entries without ensuring that the resulting file paths stay within the intended destination directory. If an attacker can influence the input image or the extraction context, they could overwrite critical files on the host system, potentially leading to remote code execution or privilege escalation. The fault is a classic file‑system traversal weakness (CWE‑22) that can directly compromise confidentiality, integrity, and availability of the affected platform.

Affected Systems

Red Hat Assisted Installer for Red Hat OpenShift Container Platform 2 and Red Hat OpenShift Container Platform 4 are impacted when using oc‑mirror to mirror operator catalogs. Specific version information is not listed, so all supported releases that include the vulnerable oc‑mirror component are affected as long as they use the legacy v1 or OCI feature extraction paths.

Risk and Exploitability

The CVSS score of 7.3 indicates a moderately high severity. The EPSS score is not available, so the current exploitation likelihood is unknown, though the flaw is straightforward to leverage where oc‑mirror is run. The vulnerability is not listed in CISA’s KEV catalog, and there is no known public exploit at this time. The attack vector is inferred to be local or remote users who have the ability to run oc‑mirror with privileges sufficient to write to the host file system. An attacker who obtains such access could place malicious files or tamper with existing configurations during catalog extraction.

Generated by OpenCVE AI on September 30, 2026 at 16:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update oc‑mirror to the latest version that fixes the path traversal issue, following the Red Hat security advisory and vendor release notes.
  • Restrict execution of oc‑mirror to trusted users and least‑privilege accounts, and use operating‑system file‑system permissions to prevent writing outside the intended directory.
  • Verify extraction directories after mirroring and audit logs for unexpected file writes to detect potential exploitation attempts.

Generated by OpenCVE AI on September 30, 2026 at 16:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Path traversal / arbitrary file write in oc-mirror's operator catalog image extraction. When mirroring operator catalogs using either the legacy v1 path (--v1) or the OCI feature path (--use-oci-feature), oc-mirror extracts tar entries from catalog image layers without validating that file paths resolve within the intended destination directory.
Title Oc-mirror: oc-mirror: path traversal / arbitrary file write in operator catalog image extraction
First Time appeared Redhat
Redhat assisted Installer
Redhat openshift
Weaknesses CWE-22
CPEs cpe:/a:redhat:assisted_installer:2
cpe:/a:redhat:openshift:4
Vendors & Products Redhat
Redhat assisted Installer
Redhat openshift
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L'}


Subscriptions

Redhat Assisted Installer Openshift
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-30T14:06:16.437Z

Reserved: 2026-09-28T13:01:18.667Z

Link: CVE-2026-101295

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T15:22:19.423

Modified: 2026-09-30T16:30:23.773

Link: CVE-2026-101295

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T16:30:12Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')