Skip to content
GoogleCVE-2026-102252

Google OSV-SCALIBR: path traversal

Medium6.9CVE-2026-102252 · Published Sep 29, 2026 · updated Sep 30, 2026

A path traversal vulnerability (CWE-22) in the embedded VMDK filesystem extractor in Google OSV-SCALIBR versions 0.3.6 through 0.5.0 allows an attacker who controls the scan target to write arbitrary files to the host system. When scanning crafted VMDK images, insufficient validation of archive path entries allows file extractions to escape destination directories.

Google advisory

Affected versions

PackageAffectedFixed in
OSV-SCALIBR
Product
>= 0.3.6, < 0.5.10.5.1
Details and references
CVSS 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-22, CWE-23

More Google advisories

All Google
Advisory
Google Chrome: improper authorization
High7.5Sep 29
Google Chrome: type confusion
High8.8Sep 29
Google Chrome: cross-site scripting
Medium6.1Sep 29
Google Chrome: improper authorization
Medium6.5Sep 29
Google Chrome: buffer overflow
Critical9.6Sep 29
Google Chrome: out-of-bounds read
Medium4.7Sep 29

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.