CVE-2026-102252: Path Traversal in VMDK Extractor in OSV-SCALIBR
A path traversal vulnerability (CWE-22) in the embedded VMDK filesystem extractor in Google OSV-SCALIBR versions 0.3.6 through 0.5.0 allows an attacker who controls the scan target to write arbitrary files to the host system. When scanning crafted VMDK images, insufficient validation of archive path entries allows file extractions to escape destination directories.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Systems running Google OSV-SCALIBR versions 0.3.6 through 0.5.0 are exposed when they scan VMDK images controlled by an attacker. The impact is arbitrary file writes on the host performing the scan.
What must an attacker control to exploit it?
The attacker must be able to provide or control the VMDK scan target. Exploitation relies on a crafted VMDK containing path entries that escape the intended extraction directory.
How can I determine whether my environment is affected?
Check whether the installed OSV-SCALIBR version is between 0.3.6 and 0.5.0 and whether it scans VMDK images from untrusted or attacker-controlled sources. The provided information does not identify a runtime indicator of prior exploitation.
What can be done if updating is not immediately possible?
Avoid scanning VMDK images from untrusted sources, since exploitation requires attacker control of the scan target. Restrict who can submit or modify VMDK scan inputs until remediation is available.