THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-j2g6-362q-6qc6 (medium) — Velero vulnerable to file path traversal when extracting from backup's tarball

[GHSA] GHSA-j2g6-362q-6qc6 (medium) — Velero vulnerable to file path traversal when extracting from backup's tarball

medgithub_advisoriesPublished 2026-08-20

GHSA-j2g6-362q-6qc6 Severity: medium CVE: CVE-2026-32637

Velero vulnerable to file path traversal when extracting from backup's tarball

### Impact _What kind of vulnerability is it? Who is impacted?_ If the attacker compromises the backup's object storage backend and uploads a malicious backup tarball including file names like the following: * ../../../tmp/escape_1 -> file created a

Indicators of compromise

Original source: https://github.com/advisories/GHSA-j2g6-362q-6qc6