CVE-2021-25741

HIGH

Kubernetes - Path Traversal

Title source: llm

Description

A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.

Exploits (3)

nomisec WORKING POC
by Glutenfree69 · poc
https://github.com/Glutenfree69/ZigRaceExploit
nomisec WORKING POC
by cdxiaodong · poc
https://github.com/cdxiaodong/CVE-2021-25741
inthewild WORKING POC
poc
https://github.com/betep0k/cve-2021-25741

Scores

CVSS v3 8.8
EPSS 0.3304
EPSS Percentile 96.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-552 CWE-20
Status published
Products (2)
k8s.io/kubernetes 0 - 1.19.15Go
kubernetes/kubernetes < 1.19.14
Published Sep 20, 2021
Tracked Since Feb 18, 2026