GHSA-8q3c-rjr9-xxrp: Path Traversal

Published Sep 3, 2026
·
Updated

Summary The VictoriaMetrics vmrestore utility does not validate backup part path components before writing restored files to the local filesystem. An attacker who can provide or modify a backup source can craft object names containing .. path components that cause vmrestore to write files outside the intended -storageDataPath restore root, subject to the permissions of the vmrestore process.

Impact An attacker who can supply or modify the backup source -- for example by writing malicious object names to a compromised or misconfigured storage bucket -- can cause arbitrary files to be created or overwritten on the host running vmrestore, within the limits of the process's filesystem permissions.

Patches Versions 1.146.0, 1.136.12, 1.122.25

Resources - https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.146.0 - https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.136.12 - https://github.com/VictoriaMetrics/VictoriaMetrics/releases/tag/v1.122.25

Note VictoriaMetrics' security model assumes backup sources are trusted and access-controlled. This vulnerability requires an attacker to have write access to the backup storage (e.g. S3, GCS, or Azure Blob Storage bucket) used as the -src for vmrestore. Under a correctly secured deployment where backup storage access is properly restricted, unauthorized exploitation of this issue should not be possible. Users are advised to follow the principle of least privilege when granting access to backup storage buckets.

Affected Software

3 affected componentsFixes available
go/github.com/VictoriaMetrics/VictoriaMetrics<1.122.25
1.122.25
go/github.com/VictoriaMetrics/VictoriaMetrics>=1.123.0<1.136.12
1.136.12
go/github.com/VictoriaMetrics/VictoriaMetrics>=1.137.0<1.146.0
1.146.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/github.com/VictoriaMetrics/VictoriaMetrics to a version that resolves this vulnerability.

    Fixed in 1.122.25
  2. Upgrade

    Upgrade go/github.com/VictoriaMetrics/VictoriaMetrics to a version that resolves this vulnerability.

    Fixed in 1.136.12
  3. Upgrade

    Upgrade go/github.com/VictoriaMetrics/VictoriaMetrics to a version that resolves this vulnerability.

    Fixed in 1.146.0
  4. Upgrade

    Upgrade VictoriaMetrics vmrestore to a version that resolves this vulnerability.

    Fixed in 1.146.0
  5. Upgrade

    Upgrade VictoriaMetrics vmrestore to a version that resolves this vulnerability.

    Fixed in 1.136.12
  6. Upgrade

    Upgrade VictoriaMetrics vmrestore to a version that resolves this vulnerability.

    Fixed in 1.122.25
  7. Compensating control

    Apply the principle of least privilege for backup storage buckets used as the -src for vmrestore (S3, GCS, or Azure Blob Storage) to restrict write access so attackers cannot supply/modify backup object names containing '..' path components.

Event History

Sep 3, 2026
Advisory Published
via GitHub·05:49 PM
Data Sourced
via GitHub·05:49 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Who is realistically exposed to this issue?

Hosts running vmrestore are exposed when they restore from a backup source an attacker can supply or modify, such as a compromised or misconfigured storage bucket. The impact is limited to files the vmrestore process has permission to create or overwrite.

2

What access does an attacker need to exploit it?

The attacker needs write access to the backup storage or another way to provide a malicious backup source. They also need a restore operation to process crafted object names containing .. path components.

3

Are trusted, access-controlled backup sources affected in practice?

VictoriaMetrics' security model assumes backup sources are trusted and access-controlled. If only trusted parties can modify the backup source, the stated attack prerequisite is not present.

4

Which versions contain patches?

Patches are available in versions 1.146.0, 1.136.12, and 1.122.25.

5

What can be done if patching cannot happen immediately?

Restrict write access to backup storage and restore only from trusted, access-controlled sources. Run vmrestore with filesystem permissions limited to the intended restore area where possible.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203