Impact
A caller-controlled TalosVersion value is passed to an image‑factory client without validation. The value may contain path‑traversal segments that the URL joining logic normalizes into unintended paths on the image‑factory host. When the backend makes HTTP GET requests to those paths, the error bodies are reflected back to the operator, allowing probing of same‑host endpoints and possible disclosure of internal diagnostics. The flaw does not allow redirection to other hosts or write operations.
Affected Systems
The affected product is Omni by siderolabs. Versions prior to 1.6.6 and 1.7.3 are vulnerable. The vulnerability is relevant for deployments that use the managementServer.CreateSchematic gRPC endpoint to create schematics on Kubernetes clusters.
Risk and Exploitability
The CVSS score of 2.7 indicates low overall impact, and the EPSS score is listed as below 1 %, reflecting a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. An authenticated Operator who can invoke CreateSchematic represents the attack scenario. The path traversal can only probe endpoints on the configured image‑factory host and does not achieve remote code execution or cross‑domain access, but it can reveal internal diagnostic information that may aid further attacks.
OpenCVE Enrichment
Github GHSA