PT-2026-75943 · Go · Github.Com/Kubev2V/Assisted-Migration-Agent

Publicado

2026-06-10

·

Atualizado

2026-06-10

CVSS v3.1

9.6

Crítica

VetorAV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal vulnerability. By crafting a specially designed gzipped tarball, the attacker can bypass security checks and write arbitrary files to the system. This could ultimately lead to the execution of unauthorized code on the appliance.

Correção

Link Following

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

GHSA-7J4W-X8X8-5MVG

Produtos afetados

Github.Com/Kubev2V/Assisted-Migration-Agent