GHSA-7j4w-x8x8-5mvgCriticalCVSS 9.6

Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution

Published
June 10, 2026
Last Modified
August 14, 2026

🔗 CVE IDs covered (1)

📋 Description

A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal vulnerability. By crafting a specially designed gzipped tarball, the attacker can bypass security checks and write arbitrary files to the system. This could ultimately lead to the execution of unauthorized code on the appliance.

🎯 Affected products1

  • go/github.com/kubev2v/assisted-migration-agent:< 0.16.0

🔗 References (6)