{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/oc-mirror/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:redhat:oc-mirror:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-101295"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["oc-mirror"],"_cs_severities":["high"],"_cs_tags":["vulnerability","path-traversal","oc-mirror","container-security","supply-chain"],"_cs_type":"threat","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eCVE-2026-101295 is a security vulnerability in the Red Hat oc-mirror utility, specifically affecting the process of extracting operator catalog image layers. The vulnerability exists in both the legacy v1 mirror path (--v1) and the OCI feature path (--use-oci-feature). During the extraction of tar entries from catalog image layers, the application fails to perform adequate input validation on file paths. Consequently, an attacker crafting a malicious catalog image can bypass directory constraints, resulting in an arbitrary file write condition on the host system where the mirror operation is performed. This flaw could be leveraged to overwrite sensitive configuration files or place malicious binaries on the filesystem, leading to unauthorized code execution or system modification.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability permits an attacker to write files to arbitrary locations on the host machine. Depending on the privileges of the user executing the oc-mirror tool, this could result in complete compromise of the local environment. This is particularly relevant for CI/CD pipelines or administrator workstations where oc-mirror is utilized to sync container images and catalogs.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate to the patched version of the oc-mirror tool immediately upon release by Red Hat. Implement strict access controls for users or service accounts permitted to execute mirror operations. Monitor command-line arguments to ensure legitimate mirror operations are constrained to expected directory structures and review local filesystem integrity after large-scale image synchronization tasks.\u003c/p\u003e\n","date_modified":"2026-10-01T10:40:54Z","date_published":"2026-09-30T18:36:06Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-101295/","summary":"A path traversal and arbitrary file write vulnerability in Red Hat's oc-mirror utility allows attackers to write files outside the intended destination directory during catalog image extraction.","title":"Path Traversal Vulnerability in oc-mirror","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-101295/"}],"language":"en","title":"CraftedSignal Threat Feed - Oc-Mirror","version":"https://jsonfeed.org/version/1.1"}