PT-2026-75943 · Go · Github.Com/Kubev2V/Assisted-Migration-Agent

Published

2026-06-10

·

Updated

2026-06-10

CVSS v3.1

9.6

Critical

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal vulnerability. By crafting a specially designed gzipped tarball, the attacker can bypass security checks and write arbitrary files to the system. This could ultimately lead to the execution of unauthorized code on the appliance.

Fix

Link Following

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-7J4W-X8X8-5MVG

Affected Products

Github.Com/Kubev2V/Assisted-Migration-Agent