Path Traversal Vulnerability in Google OSV-SCALIBR
CVE-2026-102252
6.9MEDIUM
What is CVE-2026-102252?
A path traversal vulnerability exists in the embedded VMDK filesystem extractor in Google OSV-SCALIBR versions 0.3.6 through 0.5.0. This flaw permits an attacker with control over the scan target to write arbitrary files to the host system. During the scanning of specially crafted VMDK images, inadequate validation of archive path entries results in file extractions that can circumvent designated destination directories, potentially leading to unauthorized access and system compromise.
Affected Version(s)
OSV-SCALIBR 0.3.6 < 0.5.1