[kubernetes] CVE-2026-19444: kubectl cp path traversal on Windows allows arbitrary file writes
Kubernetes assigned CVE-2026-19444 to a Windows kubectl cp path traversal that allows arbitrary file writes.
Vyom Yadav notified the Kubernetes community on oss-security about CVE-2026-19444. The flaw is a path traversal in kubectl cp on Windows that allows arbitrary file writes. It has a CVSS 3.1 score of 6.5. The published message is truncated before the full affected-version and remediation guidance.
- CVE-2026-19444 is a path traversal in kubectl cp on Windows.
- Successful use can write arbitrary files on the client.
- The issue is scored CVSS 3.1 6.5.
- Vyom Yadav disclosed it to the Kubernetes oss-security list.
Vulnerabilities mentionedAll →
- CVE-2026-194446.5—Windows kubectl cp path traversal allows arbitrary file writespublished · Kubernetes kubectl
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-19444 | Windows kubectl cp path traversal allows arbitrary file writes CVE-2026-19444 is a path traversal flaw (CWE-22) in the Kubernetes kubectl cp command, and it affects only kubectl clients running on Windows. When a user copies files out of a container, kubectl runs tar inside that container, transfers the archive, and unpacks it locally; a malicious tar binary controlled by an attacker who owns the container contents can emit crafted output that writes files to arbitrary paths on the user's machine, limited only by that local user's permissions. Triggering it requires the victim to invoke kubectl cp (user interaction) against a container the attacker already controls, with adjacent-network access and high privileges in the CVSS scoring (6.5 medium; integrity impact is high, confidentiality low, availability unchanged). Windows users of kubectl who copy from untrusted containers are the affected population; Linux and macOS clients are not affected. There is no known public proof of concept and the CVE is not listed in CISA KEV, so exploitation is none known. |
Posted by Vyom Yadav on Sep 28 Hello Kubernetes Community, https://www.first.org/cvss/calculator/3.1) (score 6.5), and assigned *CVE-2026-19444*. *Am I vulnerable?* You are...
This source does not provide full text. Read it at seclists.org.