The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, metrics and distributed traces). In versions prior to 0.2.2, the sanitizeArchivePath function in pkg/extract/extract.go (lines 248–254) is vulnerable to Path Traversal due to a missing trailing path separator in the strings.HasPrefix check. The extractor allows arbitrary file writes (e.g., overwriting shell configs, SSH keys, kubeconfig, or crontabs), enabling RCE and persistent backdoors. The attack surface is further amplified by the default ReadWriteMany PVC access mode, which lets any pod in the cluster inject a malicious payload. This issue has been fixed in version 0.2.2.
CVE-2026-32771
This critical-severity CVE scores 9.8 under NVD CVSS v3. EPSS exploit probability: 0.7%, top 52% of all CVEs by exploit prediction. GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).
- High severity, but no confirmed exploitation yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 9.8
- EG Score
- 9.8(medium)
- EG Risk
- 59(Track)EG Risk 59/100SSVC: Track
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity98% × 45%Exploitation1% × 40%Automatability100% × 15%Action: Routine — remediate on your standard cadence. - EPSS PROB
- 1%
- EPSS %ILE
- 50%
- KEV
- Not listed
Published
March 20, 2026
Last Modified
June 17, 2026
Advisory Details (3)
Auto-updated Sep 14, 2026Zip Slip Vulnerability | Snyk
https://security.snyk.io/research/zip-slip-vulnerability#expandable-socPI9fFAJ-titleArchive Slip due to missing checks in sanitization · Advisory · ctfer-io/monitoring · GitHub
https://github.com/ctfer-io/monitoring/security/advisories/GHSA-f7cq-gvh6-qr25commit 269dba165aa4 (ctfer-io/monitoring)
Patch available: ctfer-io/monitoring v0.2.2 (contains commit 269dba165aa4)
https://github.com/ctfer-io/monitoring/commit/269dba165aa42210352628c0db6756f3b8fd3c8aFrequently asked(5)
What is CVE-2026-32771?
When was CVE-2026-32771 disclosed?
Is CVE-2026-32771 actively exploited?
What is the CVSS score of CVE-2026-32771?
How do I remediate CVE-2026-32771?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2026-32771
Is Your Infrastructure Affected by CVE-2026-32771?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.