Impact
A path traversal flaw in the VMDK filesystem extractor of Google OSV-SCALIBR allows an attacker that controls the scan target to write arbitrary files to the host system. The vulnerability results from insufficient validation of archive path entries during extraction, permitting file writes outside the intended destination directory. This can lead to overwriting critical system files or installing malicious code, thereby compromising data integrity and potentially enabling further exploitation.
Affected Systems
Google OSV-SCALIBR versions 0.3.6 through 0.5.0 are affected. The flaw exists in the embedded VMDK extractor component for all releases within this range.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity risk. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is currently unpublished but still actionable. The likely attack vector is local or remote, depending on whether the scanning process permits an attacker to supply VMDK images to the OSV-SCALIBR instance. An attacker can exploit the flaw by crafting a VMDK image containing specially constructed path entries that traverse directories and write files on the host. Successful exploitation requires the attacker to have the ability to run a scan against the vulnerable instance.
OpenCVE Enrichment