CVE-2025-62878

CRITICAL

Kubernetes - Path Traversal

Title source: llm
STIX 2.1

Description

A malicious user can manipulate the parameters.pathPattern to create PersistentVolumes in arbitrary locations on the host node, potentially overwriting sensitive files or gaining access to unintended directories.

Exploits (1)

nomisec WORKING POC 1 stars
by kinokopio · poc
https://github.com/kinokopio/CVE-2025-62878

Scores

CVSS v3 9.9
EPSS 0.0003
EPSS Percentile 7.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-23
Status published
Products (2)
rancher/local-path-provisioner 0 - 0.0.34Go
SUSE/Rancher < 0.0.34
Published Feb 25, 2026
Tracked Since Feb 25, 2026