Path Traversal Vulnerability in oc-mirror
A path traversal and arbitrary file write vulnerability in Red Hat's oc-mirror utility allows attackers to write files outside the intended destination directory during catalog image extraction.
CVE search metadata
CVE search record: CVE-2026-101295. Severity: high. CVSS: 7.3. KEV: no. Product: oc-mirror. Brief: Path Traversal Vulnerability in oc-mirror. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2026-101295/
What's new
- 1. added coverage for oc-mirror Oct 1, 10:40 via nvd
CVE-2026-101295 is a security vulnerability in the Red Hat oc-mirror utility, specifically affecting the process of extracting operator catalog image layers. The vulnerability exists in both the legacy v1 mirror path (--v1) and the OCI feature path (--use-oci-feature). During the extraction of tar entries from catalog image layers, the application fails to perform adequate input validation on file paths. Consequently, an attacker crafting a malicious catalog image can bypass directory constraints, resulting in an arbitrary file write condition on the host system where the mirror operation is performed. This flaw could be leveraged to overwrite sensitive configuration files or place malicious binaries on the filesystem, leading to unauthorized code execution or system modification.
Impact
Successful exploitation of this vulnerability permits an attacker to write files to arbitrary locations on the host machine. Depending on the privileges of the user executing the oc-mirror tool, this could result in complete compromise of the local environment. This is particularly relevant for CI/CD pipelines or administrator workstations where oc-mirror is utilized to sync container images and catalogs.
Recommendation
Update to the patched version of the oc-mirror tool immediately upon release by Red Hat. Implement strict access controls for users or service accounts permitted to execute mirror operations. Monitor command-line arguments to ensure legitimate mirror operations are constrained to expected directory structures and review local filesystem integrity after large-scale image synchronization tasks.
Mitigations
Upgrade oc-mirror to the patched version once released by Red Hat
CVE-2026-101295