{"id":"GHSA-j2g6-362q-6qc6","summary":"Velero vulnerable to file path traversal when extracting from backup's tarball","details":"### Impact\n_What kind of vulnerability is it? Who is impacted?_\nIf the attacker compromises the backup's object storage backend and uploads a malicious backup tarball including file names like the following:\n* ../../../tmp/escape_1              -\u003e file created at /tmp/escape_1\n* ../../../../../../../../tmp/escape_2 -\u003e file created at /tmp/escape_2\n* ../../../tmp/cron_poc              -\u003e would be /etc/cron.d/backdoor in real attack\n* ../../../tmp/ssh_poc               -\u003e would be ~/.ssh/authorized_keys\n* ../../../tmp/kubeconfig_poc        -\u003e would be ~/.kube/config\n\nIt's possible that extracting files from the tarball during restore can overwrite sensitive files in the Velero pod filesystem. \n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\n\nBy far, there is no patch yet.\nWe are working on the main branch, then cherry-pick to the release-1.18 for v1.18.1 patch.\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\n\nThere is no workaround, but the good news is that keeping your OSS safe will prevent the vulnerability.","aliases":["CVE-2026-32637","GO-2026-6259"],"modified":"2026-08-25T20:26:09.746275978Z","published":"2026-08-20T17:26:07Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-22"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-08-20T17:26:07Z"},"references":[{"type":"WEB","url":"https://github.com/velero-io/velero/security/advisories/GHSA-j2g6-362q-6qc6"},{"type":"WEB","url":"https://github.com/securego/gosec/issues/324"},{"type":"PACKAGE","url":"https://github.com/velero-io/velero"}],"affected":[{"package":{"name":"github.com/vmware-tanzu/velero","ecosystem":"Go","purl":"pkg:golang/github.com/vmware-tanzu/velero"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.18.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-j2g6-362q-6qc6/GHSA-j2g6-362q-6qc6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}