Description
A path traversal vulnerability (CWE-22) in the embedded VMDK filesystem extractor in Google OSV-SCALIBR versions 0.3.6 through 0.5.0 allows an attacker who controls the scan target to write arbitrary files to the host system. When scanning crafted VMDK images, insufficient validation of archive path entries allows file extractions to escape destination directories.
Published: 2026-09-29
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Arbitrary File Write
Action: Immediate Patch
AI Analysis

Impact

A path traversal flaw in the VMDK filesystem extractor of Google OSV-SCALIBR allows an attacker that controls the scan target to write arbitrary files to the host system. The vulnerability results from insufficient validation of archive path entries during extraction, permitting file writes outside the intended destination directory. This can lead to overwriting critical system files or installing malicious code, thereby compromising data integrity and potentially enabling further exploitation.

Affected Systems

Google OSV-SCALIBR versions 0.3.6 through 0.5.0 are affected. The flaw exists in the embedded VMDK extractor component for all releases within this range.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity risk. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is currently unpublished but still actionable. The likely attack vector is local or remote, depending on whether the scanning process permits an attacker to supply VMDK images to the OSV-SCALIBR instance. An attacker can exploit the flaw by crafting a VMDK image containing specially constructed path entries that traverse directories and write files on the host. Successful exploitation requires the attacker to have the ability to run a scan against the vulnerable instance.

Generated by OpenCVE AI on September 29, 2026 at 21:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google OSV‑SCALIBR to the latest release that removes the path‑traversal flaw (version 0.5.1 or newer).
  • If an immediate upgrade is not possible, restrict the OSV‑SCALIBR environment so that it only processes trusted VMDK images and denies or validates any path components before extraction.
  • Implement host‑level access controls to ensure that the OSV‑SCALIBR process runs with the least privilege necessary, limiting the impact of any accidental file writes.

Generated by OpenCVE AI on September 29, 2026 at 21:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google osv-scalibr
Vendors & Products Google
Google osv-scalibr

Tue, 29 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A path traversal vulnerability (CWE-22) in the embedded VMDK filesystem extractor in Google OSV-SCALIBR versions 0.3.6 through 0.5.0 allows an attacker who controls the scan target to write arbitrary files to the host system. When scanning crafted VMDK images, insufficient validation of archive path entries allows file extractions to escape destination directories.
Title Path Traversal in VMDK Extractor in OSV-SCALIBR
Weaknesses CWE-22
CWE-23
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Google Osv-scalibr
cve-icon MITRE

Status: PUBLISHED

Assigner: Google

Published:

Updated: 2026-09-29T19:41:42.440Z

Reserved: 2026-09-28T19:17:24.232Z

Link: CVE-2026-102252

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T20:17:11.910

Modified: 2026-09-29T21:36:39.547

Link: CVE-2026-102252

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T20:45:19Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-23

    Relative Path Traversal