A malicious user can manipulate the parameters.pathPattern to create PersistentVolumes in arbitrary locations on the host node, potentially overwriting sensitive files or gaining access to unintended directories.
Project Subscriptions
No data.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-jr3w-9vfr-c746 | Local Path Provisioner vulnerable to Path Traversal via parameters.pathPattern |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 25 Feb 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A malicious user can manipulate the parameters.pathPattern to create PersistentVolumes in arbitrary locations on the host node, potentially overwriting sensitive files or gaining access to unintended directories. | |
| Title | Local Path Provisioner vulnerable to Path Traversal via parameters.pathPattern | |
| Weaknesses | CWE-23 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: suse
Published:
Updated: 2026-02-25T10:50:22.691Z
Reserved: 2025-10-24T10:34:22.765Z
Link: CVE-2025-62878
No data.
Status : Awaiting Analysis
Published: 2026-02-25T11:16:01.747
Modified: 2026-02-25T14:15:29.980
Link: CVE-2025-62878
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA