Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-19444— Kubernetes kubectl cp path traversal on Windows allows arbitrary file writes

Quick assessment

Affected
Kubernetes Kubernetes
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Kubernetes 的 客户端中,Windows 平台上的 命令存在一个路径遍历漏洞。当从容器中复制文件时, 会在容器内部执行 命令以构建 tar 归档文件,通过网络将其传输到本地机器,并在本地解包。如果容器内的 二进制文件是恶意的,攻击者可能执行任意代码并产生非预期的输出,从而在调用 时,将文件写入本地用户机器上的任意路径(受限于本地用户的系统权限)。该问题仅影响运行在 Windows 系统上的 客户端。

CVSS 6.5 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-19444

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Kubernetes kubectl cp path traversal on Windows allows arbitrary file writes
Source: CVE Program / CVE List V5
Vulnerability Description
A path traversal vulnerability was discovered in the Kubernetes kubectl client's kubectl cp command on Windows. When copying files from a container, kubectl runs tar inside the container to build a tar archive, transfers it over the network, and unpacks it on the local machine. If the tar binary in the container is malicious, it can execute arbitrary code and emit unexpected output, allowing an attacker who controls container contents to write files to arbitrary paths on the user's local machine when kubectl cp is invoked, limited only by the system permissions of the local user. This issue only affects kubectl clients running on Windows.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Kubernetes Kubernetes v1.36.0 ~ v1.36.4 -

II. Public POCs for CVE-2026-19444

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-19444

请登录查看更多情报信息。

Other References for CVE-2026-19444 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-19444

No comments yet


Leave a comment