Path Traversal in Rancher Local Path Provisioner Enables Host Filesystem Compromise Across K3s Clusters

Introduction A critical vulnerability (CVE-2025-62878, CVSS 10.0) was disclosed on February 4, 2026 affecting all versions of Rancher’s Local Path Provisioner prior to v0.0.34, the default storage backend for every K3s cluster. The flaw allows authenticated attackers to read, write, and delete arbitrary directories on the underlying host filesystem by injecting traversal sequences into a […]

The post Path Traversal in Rancher Local Path Provisioner Enables Host Filesystem Compromise Across K3s Clusters appeared first on Orca Security.

原始链接: https://orca.security/resources/blog/cve-2025-62878-rancher-local-path-provisioner/
侵权请联系站方: [email protected]

相关推荐

换一批