Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
GHSA-9vm9-pqxx-x83v
Description
KubeEdge keadm contains a path traversal vulnerability in the DecompressTarGz archive extraction function.
Archive entry names were joined directly with the extraction destination without sufficient validation. A crafted tar.gz archive containing parent-directory components, Windows-style backslashes, absolute paths, or drive-prefixed paths could cause files to be written outside the intended extraction directory.
The issue is particularly relevant to Windows edge nodes during the keadm join or installation process when keadm extracts downloaded component archives.
Impact
An attacker who can cause an affected keadm process to extract a malicious archive may write or overwrite files outside the intended destination directory with the privileges of the user running keadm.
On Windows edge nodes, this may allow modification of configuration files, executable files, service-related files, or other writable system locations. Depending on the overwritten file and the privileges of the keadm process, successful exploitation could lead to persistent system modification or code execution.
Exploitation requires the attacker to influence the contents of an archive processed by keadm, such as through a compromised, replaced, or otherwise untrusted download source.
Patches
The extraction logic now:
- resolves the destination directory to an absolute path;
- rejects empty archive entry names;
- normalizes Windows-style path separators before validation;
- rejects parent-directory traversal paths;
- rejects absolute and Windows drive-prefixed paths;
- uses
filepath-securejointo ensure extracted files remain within the destination directory.
Fixes are planned for the following maintained releases:
- v1.23.1
- v1.22.2
- v1.21.2
Workarounds
Until a patched release is available:
- only install or join edge nodes using trusted KubeEdge package sources;
- verify the integrity and origin of downloaded archives before extraction;
- do not use custom or untrusted component archives with
keadm; - restrict write permissions and administrative privileges for the account running
keadm; - avoid performing Windows edge-node installation or join operations when the package source cannot be trusted.
Credits
KubeEdge thanks Sang-Hoon Choi (KoreaSecurity, Sejong University) for responsibly reporting this issue and for coordinating with the KubeEdge maintainers through the security disclosure process.
Upload your own SBOM in CycloneDX 1.6 or higher (JSON) directly here to check your vulnerabilities.
Drag and drop some file here, or click to select
The vulnerability can be exploited over the network without needing physical access. It is easy for an attacker to exploit this vulnerability. An attacker does not need any special privileges or access rights. The attacker needs the user to perform some action, like clicking a link. The impact is confined to the system where the vulnerability exists. There is a high impact on the integrity of the data. There is a high impact on the availability of the system.
Exploitation activity has been observed. Apply available patches or mitigations urgently.
The exploit probability is very low. The vulnerability is unlikely to be exploited in the next 30 days.
We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.
Browse More
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard