{"id":"CVE-2026-101295","title":"Path traversal / arbitrary file write in oc-mirror's operator catalog image extraction","summary":"Path traversal / arbitrary file write in oc-mirror's operator catalog image extraction. When mirroring operator catalogs using either the legacy v1 path (--v1) or the OCI feature path (--use-oci-feature), oc-mirror extracts tar entries f…","severity":"high","cvss":7.3,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L","cwe":["CWE-22"],"vendor":"Red Hat","product":"assisted/agent-preinstall-image-builder-rhel9","affected":["assisted/agent-preinstall-image-builder-rhel9","openshift4/oc-mirror-plugin-rhel8","openshift4/oc-mirror-plugin-rhel9"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T16:30:23.773","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-101295","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-101295","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2522941","label":"secalert@redhat.com"},{"url":"https://github.com/openshift/oc-mirror/blob/22a5722/v1/pkg/cli/mirror/catalog_images.go#L680","label":"secalert@redhat.com"},{"url":"https://github.com/openshift/oc-mirror/blob/22a5722/v1/pkg/cli/mirror/fbc_operators.go#L334-L369","label":"secalert@redhat.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-30T15:07:05.390Z","slug":"CVE-2026-101295","body":"## Overview\n\nPath traversal / arbitrary file write in oc-mirror's operator catalog image extraction. When mirroring operator catalogs using either the legacy v1 path (--v1) or the OCI feature path (--use-oci-feature), oc-mirror extracts tar entries from catalog image layers without validating that file paths resolve within the intended destination directory.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":40.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}