Back to CVE List

CVE-2025-62878

CRITICAL SEVERITY

CVSS Score & Metrics

Base Score
10.0 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Vulnerability Description

A malicious user can manipulate the parameters.pathPattern to create PersistentVolumes in arbitrary locations on the host node, potentially overwriting sensitive files or gaining access to unintended directories.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-23
Source
GitHub
Vendor
go
Product
github.com/rancher/local-path-provisioner

External References

Discussion (0)

Add Comment

No comments yet. Be the first!