THREAT OPS › Threat News › [GHSA] GHSA-j2g6-362q-6qc6 (medium) — Velero vulnerable to file path traversal when extracting from backup's tarball
[GHSA] GHSA-j2g6-362q-6qc6 (medium) — Velero vulnerable to file path traversal when extracting from backup's tarball
GHSA-j2g6-362q-6qc6 Severity: medium CVE: CVE-2026-32637
Velero vulnerable to file path traversal when extracting from backup's tarball
### Impact _What kind of vulnerability is it? Who is impacted?_ If the attacker compromises the backup's object storage backend and uploads a malicious backup tarball including file names like the following: * ../../../tmp/escape_1 -> file created a
Indicators of compromise
- CVE-2026-32637cve
Original source: https://github.com/advisories/GHSA-j2g6-362q-6qc6