CVE-2026-103870: Pulp-rpm: distribution tree publish creates directories from .treeinfo ids

Published Oct 1, 2026
·
Updated

A flaw was found in pulp-rpm when it publishes a distribution tree. Addon and variant ids from .treeinfo are used as directory names. A user who can sync or upload that tree can make the publish task create a new directory outside the task work area and write that tree's repository metadata and packages there, as the Pulp worker user. An existing file or directory is not replaced. The flaw does not disclose data and does not stop the service.

Other sources

Publish copies the addon id and variant id from .treeinfo into addonid and variantid with no path check (pulprpm/app/kickstart/treeinfo.py). RpmPublication.populate() then calls os.mkdir(name) with that string (pulprpm/app/tasks/publishing.py) and writes the synced metadata and packages under that name. os.mkdir does not create missing parents, and it fails when the path already exists, so an existing file is not replaced. A ".." component or an absolute id whose parent exists leaves the worker temporary directory. The same code runs for any repository version that contains a distribution tree. No extra setting selects it. Introduced with kickstart publishing in 8a8048e2, tag 3.0.0b5, and every stable release from 3.2.0.

— Red Hat

Affected Software

1 affected component
Pulp pulp-rpm>=3.0.0b5

Event History

Oct 1, 2026
Data Sourced
via Red Hat·12:30 PM
DescriptionSeverityAffected Software
Oct 7, 2026
CVE Published
via MITRE·05:46 AM
Data Sourced
via MITRE·05:46 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

A user who can sync or upload a distribution tree can supply addon or variant IDs in .treeinfo that are used during publication. The issue affects any repository version containing a distribution tree.

2

Is a special configuration required for exposure?

No. The vulnerable publishing code runs for distribution trees without an additional setting selecting it, and the same code path applies to any repository version that contains one.

3

What does an attacker need to make the publish task write outside its work area?

They need to provide a .treeinfo addon or variant ID containing a ".." component, or an absolute path whose parent directory already exists. Missing parent directories are not created, and an existing file or directory at the target path is not replaced.

4

What is the practical impact of successful exploitation?

The Pulp worker can create a new directory outside its task work area and write the supplied tree's repository metadata and packages there, using the Pulp worker user's permissions. The flaw does not disclose data or stop the service.

5

Which releases are affected?

The issue was introduced with kickstart publishing in tag 3.0.0b5 and affects every stable release from 3.2.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203