CVE-2026-102252
Awaiting Analysis Awaiting Analysis - Queue

Path Traversal in Google OSV-SCALIBR VMDK Extractor

Vulnerability report for CVE-2026-102252, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Google Inc.

Description

A path traversal vulnerability (CWE-22) in the embedded VMDK filesystem extractor in Google OSV-SCALIBR versions 0.3.6 through 0.5.0 allows an attacker who controls the scan target to write arbitrary files to the host system. When scanning crafted VMDK images, insufficient validation of archive path entries allows file extractions to escape destination directories.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-30
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
google osv-scalibr From 0.3.6 (inc) to 0.5.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-23 The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a path traversal vulnerability in Google OSV-SCALIBR versions 0.3.6 through 0.5.0. It allows an attacker who controls the scan target to write arbitrary files to the host system by exploiting crafted VMDK images. The issue occurs because the embedded VMDK filesystem extractor does not properly validate archive path entries, enabling file extractions to escape intended destination directories.

Impact Analysis

If you use Google OSV-SCALIBR in versions 0.3.6 to 0.5.0, an attacker could exploit this to overwrite or create malicious files on your system. This could lead to system compromise, data corruption, or unauthorized access depending on the files targeted.

Mitigation Strategies

Immediately upgrade Google OSV-SCALIBR to a version outside the vulnerable range (0.3.6 through 0.5.0). Avoid scanning untrusted VMDK images until patched. Implement network segmentation to limit exposure of systems running vulnerable versions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102252. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart