---
id: CVE-2026-101295
title: >-
  Path traversal / arbitrary file write in oc-mirror's operator catalog image
  extraction
summary: >-
  Path traversal / arbitrary file write in oc-mirror's operator catalog image
  extraction. When mirroring operator catalogs using either the legacy v1 path
  (--v1) or the OCI feature path (--use-oci-feature), oc-mirror extracts tar
  entries f…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L'
cwe:
  - CWE-22
vendor: Red Hat
product: assisted/agent-preinstall-image-builder-rhel9
affected:
  - assisted/agent-preinstall-image-builder-rhel9
  - openshift4/oc-mirror-plugin-rhel8
  - openshift4/oc-mirror-plugin-rhel9
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T16:30:23.773'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-101295'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2026-101295'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2522941'
    label: secalert@redhat.com
  - url: >-
      https://github.com/openshift/oc-mirror/blob/22a5722/v1/pkg/cli/mirror/catalog_images.go#L680
    label: secalert@redhat.com
  - url: >-
      https://github.com/openshift/oc-mirror/blob/22a5722/v1/pkg/cli/mirror/fbc_operators.go#L334-L369
    label: secalert@redhat.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T15:07:05.390Z'
---

## Overview

Path traversal / arbitrary file write in oc-mirror's operator catalog image extraction. When mirroring operator catalogs using either the legacy v1 path (--v1) or the OCI feature path (--use-oci-feature), oc-mirror extracts tar entries from catalog image layers without validating that file paths resolve within the intended destination directory.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
