Skip to content
Threat Feed
critical advisory

Arbitrary File Deletion via Path Traversal in gvproxy

An unauthenticated path traversal vulnerability in the gvproxy component of gvisor-tap-vsock allows attackers to delete arbitrary files on the host filesystem via the /services/forwarder/expose endpoint.

CVE search metadata

CVE search record: CVE-2026-107935. Severity: critical. CVSS: 9.3. KEV: no. Product: gvproxy (gvisor-tap-vsock). Brief: Arbitrary File Deletion via Path Traversal in gvproxy. Brief link: https://feed.craftedsignal.io/briefs/2026-10-gvproxy-path-traversal/

CVE-2026-107935 is a critical path traversal vulnerability residing in gvproxy, which serves as a network forwarder within the gvisor-tap-vsock package. The flaw exists due to insufficient input validation on the /services/forwarder/expose API endpoint. By submitting a crafted request containing a malicious socket path, an unauthenticated attacker can manipulate the application to perform file operations outside of the intended directory. Because the application interacts directly with the host system, this lack of path sanitization allows an attacker to trigger the deletion of arbitrary files on the host filesystem. This vulnerability poses a significant risk to the integrity of systems utilizing gvproxy, particularly in containerized or virtualized environments where host-level access is highly sensitive. Defenders should prioritize auditing web-based logs for suspicious POST requests to the affected endpoint and identify deployments of gvisor-tap-vsock to prepare for patching.

Impact

Successful exploitation of this vulnerability results in arbitrary file deletion on the host operating system. This can lead to system instability, service disruption, or the removal of sensitive configuration files and security-critical binaries. Any environment utilizing the gvisor-tap-vsock stack for network forwarding is potentially at risk of host-level impact if the gvproxy service is exposed to an untrusted network.

Recommendation

  • Monitor webserver and proxy logs for incoming requests targeting the /services/forwarder/expose URI to identify potential exploitation attempts.
  • Audit environments to locate instances of gvisor-tap-vsock and gvproxy.
  • Apply patches immediately upon release by the maintainers of the gvisor-tap-vsock package.
  • Ensure that the gvproxy endpoint is restricted to authorized internal traffic only, preventing unauthenticated access from untrusted sources.

Immediate actions

Deploy Sigma detection rule to web server logs

Detection Engineering 24h

Mitigations

Identify and restrict access to the /services/forwarder/expose endpoint

immediate IT Operations

CVE-2026-107935

Detection coverage 1

Detect CVE-2026-107935 Exploitation - Path Traversal in gvproxy

critical

Detects potential exploitation attempts of CVE-2026-107935 by monitoring for suspicious path traversal patterns in the socket path parameter of the /services/forwarder/expose endpoint.

sigma tactics: impact, initial_access techniques: T1005 sources: webserver

Detection queries are available on the platform. Get full rules →