PT-2026-79061 · Unknown · Victoriametrics

CVE-2026-61625

·

Published

2026-08-20

·

Updated

2026-09-03

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions VictoriaMetrics versions prior to 1.122.25 VictoriaMetrics versions prior to 1.136.12 VictoriaMetrics versions prior to 1.146.0
Description The vmrestore tool fails to validate backup part path components before writing restored data below storageDataPath using lib/backup/actions/restore.go and lib/backup/fslocal/fslocal.go. An attacker capable of supplying or modifying a backup source, such as S3, GCS, or Azure Blob Storage, can include path traversal components (..) in object names. During the restoration process, these crafted names allow the creation or overwriting of files outside the intended restore root, limited by the filesystem permissions of the vmrestore process.
Recommendations Update to version 1.122.25 or later. Update to version 1.136.12 or later. Update to version 1.146.0 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61625
GHSA-8Q3C-RJR9-XXRP

Affected Products

Victoriametrics