github.com/kubev2v/migration-planner
Go4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/kubev2v/migration-plannerpage 1 of 1
- CVE-2026-53469CRITICALCVSS 8.1EG 9.1✓ Fixed in 0.13.52026-06-10
A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by sending a DELETE request to the /api/v1/sources route, which lacks proper authorization and filtering. This allows for the destruction of all cu…
- CVE-2026-53470CRITICALCVSS 8.1EG 9.6✓ Fixed in 0.13.52026-06-10
A flaw was found in migration-planner. An authenticated attacker could exploit an improper access control vulnerability in the `/api/v1/sources/{id}/image-url` endpoint. This flaw allows the attacker to bypass an ownership check and obtain…
- CVE-2026-53471CRITICALCVSS 7.7EG 9.6✓ Fixed in 0.13.52026-06-10
A flaw was found in migration-planner. The agent-API middleware processes JSON Web Tokens (JWTs) for authentication, but its UpdateSourceInventory and UpdateAgentStatus handlers fail to validate the source_id claim within these tokens agai…
- CVE-2026-53474CRITICALCVSS 6.5EG 9.6✓ Fixed in 0.13.52026-06-10
A flaw was found in migration-planner. A remote authenticated attacker could exploit this vulnerability by uploading a specially crafted RVTools .xlsx file. Due to improper input sanitization, malicious SQL embedded within a spreadsheet ce…
Check whether github.com/kubev2v/migration-planner is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/kubev2v/migration-planner CVEs against the assets you own.
Start Free Scan →