[kubernetes] CVE-2026-19444: kubectl cp path traversal on Windows allows arbitrary file writes
Kubernetes assigned CVE-2026-19444 to a Windows kubectl cp path traversal that allows arbitrary file writes.
Vyom Yadav notified the Kubernetes community on oss-security about CVE-2026-19444. The flaw is a path traversal in kubectl cp on Windows that allows arbitrary file writes. It has a CVSS 3.1 score of 6.5. The published message is truncated before the full affected-version and remediation guidance.
46