Path Traversal Vulnerability in VictoriaMetrics Product
CVE-2026-61625
What is CVE-2026-61625?
VictoriaMetrics, a robust solution for monitoring time series data, contained a vulnerability in its vmrestore functionality prior to versions 1.122.25, 1.136.12, and 1.146.0. The vulnerability occurs when the backup path components are not sufficiently validated, allowing malicious users to manipulate S3, GCS, or Azure Blob Storage object names. This oversight enables an attacker to leverage crafted object names to create or overwrite files outside the designated restore directory, which may compromise the integrity of the filesystem permissions associated with the vmrestore process. Users are urged to update to the specified patched versions to mitigate this risk.
Affected Version(s)
VictoriaMetrics >= 1.137.0, < 1.146.0 < 1.137.0, 1.146.0
VictoriaMetrics >= 1.123.0, < 1.136.12 < 1.123.0, 1.136.12
VictoriaMetrics < 1.122.25 < 1.122.25
