Arbitrary File Deletion via Path Traversal in gvproxy
An unauthenticated path traversal vulnerability in the gvproxy component of gvisor-tap-vsock allows attackers to delete arbitrary files on the host filesystem via the /services/forwarder/expose endpoint.
CVE search metadata
CVE search record: CVE-2026-107935. Severity: critical. CVSS: 9.3. KEV: no. Product: gvproxy (gvisor-tap-vsock). Brief: Arbitrary File Deletion via Path Traversal in gvproxy. Brief link: https://feed.craftedsignal.io/briefs/2026-10-gvproxy-path-traversal/
CVE-2026-107935 is a critical path traversal vulnerability residing in gvproxy, which serves as a network forwarder within the gvisor-tap-vsock package. The flaw exists due to insufficient input validation on the /services/forwarder/expose API endpoint. By submitting a crafted request containing a malicious socket path, an unauthenticated attacker can manipulate the application to perform file operations outside of the intended directory. Because the application interacts directly with the host system, this lack of path sanitization allows an attacker to trigger the deletion of arbitrary files on the host filesystem. This vulnerability poses a significant risk to the integrity of systems utilizing gvproxy, particularly in containerized or virtualized environments where host-level access is highly sensitive. Defenders should prioritize auditing web-based logs for suspicious POST requests to the affected endpoint and identify deployments of gvisor-tap-vsock to prepare for patching.
Impact
Successful exploitation of this vulnerability results in arbitrary file deletion on the host operating system. This can lead to system instability, service disruption, or the removal of sensitive configuration files and security-critical binaries. Any environment utilizing the gvisor-tap-vsock stack for network forwarding is potentially at risk of host-level impact if the gvproxy service is exposed to an untrusted network.
Recommendation
- Monitor webserver and proxy logs for incoming requests targeting the /services/forwarder/expose URI to identify potential exploitation attempts.
- Audit environments to locate instances of gvisor-tap-vsock and gvproxy.
- Apply patches immediately upon release by the maintainers of the gvisor-tap-vsock package.
- Ensure that the gvproxy endpoint is restricted to authorized internal traffic only, preventing unauthenticated access from untrusted sources.
Immediate actions
Deploy Sigma detection rule to web server logs
Mitigations
Identify and restrict access to the /services/forwarder/expose endpoint
CVE-2026-107935
Detection coverage 1
Detect CVE-2026-107935 Exploitation - Path Traversal in gvproxy
criticalDetects potential exploitation attempts of CVE-2026-107935 by monitoring for suspicious path traversal patterns in the socket path parameter of the /services/forwarder/expose endpoint.
Detection queries are available on the platform. Get full rules →