{"id":"GHSA-9vm9-pqxx-x83v","summary":"KubeEdge: keadm DecompressTarGz path traversal enables arbitrary file write on Windows during edge node join","details":"## Description\n\nKubeEdge `keadm` contains a path traversal vulnerability in the `DecompressTarGz` archive extraction function.\n\nArchive entry names were joined directly with the extraction destination without sufficient validation. A crafted tar.gz archive containing parent-directory components, Windows-style backslashes, absolute paths, or drive-prefixed paths could cause files to be written outside the intended extraction directory.\n\nThe issue is particularly relevant to Windows edge nodes during the `keadm join` or installation process when `keadm` extracts downloaded component archives.\n\n## Impact\n\nAn attacker who can cause an affected `keadm` process to extract a malicious archive may write or overwrite files outside the intended destination directory with the privileges of the user running `keadm`.\n\nOn Windows edge nodes, this may allow modification of configuration files, executable files, service-related files, or other writable system locations. Depending on the overwritten file and the privileges of the `keadm` process, successful exploitation could lead to persistent system modification or code execution.\n\nExploitation requires the attacker to influence the contents of an archive processed by `keadm`, such as through a compromised, replaced, or otherwise untrusted download source.\n\n## Patches\n\nThe extraction logic now:\n\n* resolves the destination directory to an absolute path;\n* rejects empty archive entry names;\n* normalizes Windows-style path separators before validation;\n* rejects parent-directory traversal paths;\n* rejects absolute and Windows drive-prefixed paths;\n* uses `filepath-securejoin` to ensure extracted files remain within the destination directory.\n\nFixes are planned for the following maintained releases:\n\n* v1.23.1\n* v1.22.2\n* v1.21.2\n\n## Workarounds\n\nUntil a patched release is available:\n\n* only install or join edge nodes using trusted KubeEdge package sources;\n* verify the integrity and origin of downloaded archives before extraction;\n* do not use custom or untrusted component archives with `keadm`;\n* restrict write permissions and administrative privileges for the account running `keadm`;\n* avoid performing Windows edge-node installation or join operations when the package source cannot be trusted.\n\n## Credits\n\nKubeEdge thanks Sang-Hoon Choi ([KoreaSecurity](https://github.com/KoreaSecurity), Sejong University)\nfor responsibly reporting this issue and for coordinating with the KubeEdge\nmaintainers through the security disclosure process.","aliases":["CVE-2026-62369","GO-2026-6563"],"modified":"2026-10-01T20:55:52.777452175Z","published":"2026-09-22T20:36:59Z","database_specific":{"nvd_published_at":"2026-09-21T18:17:09Z","cwe_ids":["CWE-22"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-09-22T20:36:59Z"},"references":[{"type":"WEB","url":"https://github.com/kubeedge/kubeedge/security/advisories/GHSA-9vm9-pqxx-x83v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62369"},{"type":"WEB","url":"https://github.com/kubeedge/kubeedge/pull/7028"},{"type":"WEB","url":"https://github.com/kubeedge/kubeedge/pull/7029"},{"type":"WEB","url":"https://github.com/kubeedge/kubeedge/pull/7030"},{"type":"WEB","url":"https://github.com/kubeedge/kubeedge/commit/47767b7f2649afcfa3a856e87d556f7777e0428d"},{"type":"WEB","url":"https://github.com/kubeedge/kubeedge/commit/a524a66a1ae1691eb8ff16b6ff9a93fb370d4047"},{"type":"WEB","url":"https://github.com/kubeedge/kubeedge/commit/ee02dea9d08114afc4a8f401b1c2f30e84e1de40"},{"type":"PACKAGE","url":"https://github.com/kubeedge/kubeedge"},{"type":"WEB","url":"https://github.com/kubeedge/kubeedge/blob/master/CHANGELOG/CHANGELOG-1.21.md"},{"type":"WEB","url":"https://github.com/kubeedge/kubeedge/blob/master/CHANGELOG/CHANGELOG-1.22.md"},{"type":"WEB","url":"https://github.com/kubeedge/kubeedge/blob/master/CHANGELOG/CHANGELOG-1.23.md"},{"type":"WEB","url":"https://github.com/kubeedge/kubeedge/releases/tag/v1.21.2"},{"type":"WEB","url":"https://github.com/kubeedge/kubeedge/releases/tag/v1.22.2"},{"type":"WEB","url":"https://github.com/kubeedge/kubeedge/releases/tag/v1.23.1"}],"affected":[{"package":{"name":"github.com/kubeedge/kubeedge","ecosystem":"Go","purl":"pkg:golang/github.com/kubeedge/kubeedge"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.16.0"},{"fixed":"1.21.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-9vm9-pqxx-x83v/GHSA-9vm9-pqxx-x83v.json"}},{"package":{"name":"github.com/kubeedge/kubeedge","ecosystem":"Go","purl":"pkg:golang/github.com/kubeedge/kubeedge"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.22.0"},{"fixed":"1.22.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-9vm9-pqxx-x83v/GHSA-9vm9-pqxx-x83v.json"}},{"package":{"name":"github.com/kubeedge/kubeedge","ecosystem":"Go","purl":"pkg:golang/github.com/kubeedge/kubeedge"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.23.0"},{"fixed":"1.23.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-9vm9-pqxx-x83v/GHSA-9vm9-pqxx-x83v.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"}]}