<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Oc-Mirror - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/oc-mirror/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 30 Sep 2026 18:36:06 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/oc-mirror/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Path Traversal Vulnerability in oc-mirror</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-101295/</link><pubDate>Wed, 30 Sep 2026 18:36:06 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-101295/</guid><description>A path traversal and arbitrary file write vulnerability in Red Hat's oc-mirror utility allows attackers to write files outside the intended destination directory during catalog image extraction.</description><content:encoded><![CDATA[<p>CVE-2026-101295 is a security vulnerability in the Red Hat oc-mirror utility, specifically affecting the process of extracting operator catalog image layers. The vulnerability exists in both the legacy v1 mirror path (--v1) and the OCI feature path (--use-oci-feature). During the extraction of tar entries from catalog image layers, the application fails to perform adequate input validation on file paths. Consequently, an attacker crafting a malicious catalog image can bypass directory constraints, resulting in an arbitrary file write condition on the host system where the mirror operation is performed. This flaw could be leveraged to overwrite sensitive configuration files or place malicious binaries on the filesystem, leading to unauthorized code execution or system modification.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability permits an attacker to write files to arbitrary locations on the host machine. Depending on the privileges of the user executing the oc-mirror tool, this could result in complete compromise of the local environment. This is particularly relevant for CI/CD pipelines or administrator workstations where oc-mirror is utilized to sync container images and catalogs.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update to the patched version of the oc-mirror tool immediately upon release by Red Hat. Implement strict access controls for users or service accounts permitted to execute mirror operations. Monitor command-line arguments to ensure legitimate mirror operations are constrained to expected directory structures and review local filesystem integrity after large-scale image synchronization tasks.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>vulnerability</category><category>path-traversal</category><category>oc-mirror</category><category>container-security</category><category>supply-chain</category></item></channel></rss>