A path traversal vulnerability (CWE-22) in the embedded VMDK filesystem extractor in Google OSV-SCALIBR versions 0.3.6 through 0.5.0 allows an attacker who controls the scan target to write arbitrary files to the host system. When scanning crafted VMDK images, insufficient validation of archive path entries allows file extractions to escape destination directories.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 29 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A path traversal vulnerability (CWE-22) in the embedded VMDK filesystem extractor in Google OSV-SCALIBR versions 0.3.6 through 0.5.0 allows an attacker who controls the scan target to write arbitrary files to the host system. When scanning crafted VMDK images, insufficient validation of archive path entries allows file extractions to escape destination directories.
Title Path Traversal in VMDK Extractor in OSV-SCALIBR
Weaknesses CWE-22
CWE-23
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Google

Published:

Updated: 2026-09-29T19:41:42.440Z

Reserved: 2026-09-28T19:17:24.232Z

Link: CVE-2026-102252

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T20:17:11.910

Modified: 2026-09-29T20:17:11.910

Link: CVE-2026-102252

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses