A malicious user can manipulate the parameters.pathPattern to create PersistentVolumes in arbitrary locations on the host node, potentially overwriting sensitive files or gaining access to unintended directories.
Metrics
Affected Vendors & Products
References
History
Wed, 25 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 25 Feb 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A malicious user can manipulate the parameters.pathPattern to create PersistentVolumes in arbitrary locations on the host node, potentially overwriting sensitive files or gaining access to unintended directories. | |
| Title | Local Path Provisioner vulnerable to Path Traversal via parameters.pathPattern | |
| Weaknesses | CWE-23 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: suse
Published: 2026-02-25T10:49:29.596Z
Updated: 2026-02-26T14:44:06.924Z
Reserved: 2025-10-24T10:34:22.765Z
Link: CVE-2025-62878
Updated: 2026-02-25T20:47:56.648Z
Status : Awaiting Analysis
Published: 2026-02-25T11:16:01.747
Modified: 2026-02-25T14:15:29.980
Link: CVE-2025-62878
No data.