logo

CVE-2025-62878: Critical 10.0 Vulnerability Found in Kubernetes Local Path Provisioner

ID: 410ab2ce-cdda-593d-8d9c-75ef1f53ab9f

STIX ID: report--410ab2ce-cdda-593d-8d9c-75ef1f53ab9f

Feed Name: securityonline.info

Threat Score
95/100

Date Published: 2026-02-09

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical path traversal vulnerability (CVE-2025-62878) in the SUSE Rancher Local Path Provisioner allows attackers to escape the configured storage base path via the pathPattern parameter and create PersistentVolumes in arbitrary host locations (including /etc), potentially overwriting sensitive files or planting malicious scripts; the flaw carries a CVSS score of 10.0, maintainers released v0.0.34 to fix it, and there are no workarounds—administrators must upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.