Path Traversal Vulnerability in Google OSV-SCALIBR
CVE-2026-102252

6.9MEDIUM

Key Information:

Vendor

Google

Vendor
CVE Published:
29 September 2026

What is CVE-2026-102252?

A path traversal vulnerability exists in the embedded VMDK filesystem extractor in Google OSV-SCALIBR versions 0.3.6 through 0.5.0. This flaw permits an attacker with control over the scan target to write arbitrary files to the host system. During the scanning of specially crafted VMDK images, inadequate validation of archive path entries results in file extractions that can circumvent designated destination directories, potentially leading to unauthorized access and system compromise.

Affected Version(s)

OSV-SCALIBR 0.3.6 < 0.5.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0xXA (https://github.com/0xXA)
.