{"id":"GHSA-jxr7-mqhw-9p98","summary":"K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression","details":"#### Summary\n\nA path traversal vulnerability exists in K3s's etcd snapshot decompression functionality. Zip files containing archive members with maliciously crafted names (e.g., `../../../../etc/password`) can be written to arbitrary locations on the filesystem when an administrator restores the archive as a compressed etcd snapshot.\n\n#### Mitigations\n\n* Enable golang's built-in [insecure path protections](https://pkg.go.dev/archive/zip#NewReader) when restoring snapshots by setting the`GODEBUG` environment variable:\n    ```bash\n    GODEBUG=zipinsecurepath=0 k3s server --cluster-reset --cluster-reset-restore-path=/path/to/snapshot.zip\n    ```\n* Manually extract the snapshot from the zip archive before restoring it. If the snapshot to be restored does not end with `.zip`, the vulnerable extraction code will not be executed.\n\n#### Additional Notes\n\nAdministrators should be aware of the cautions noted in the \"Security\" section of the documentation on [Restoring Snapshots](https://docs.k3s.io/cli/etcd-snapshot#security).","aliases":["CVE-2026-54250","GO-2026-5973"],"modified":"2026-09-10T03:50:52.566036718Z","published":"2026-07-14T17:54:14Z","database_specific":{"nvd_published_at":"2026-06-25T19:16:41Z","cwe_ids":["CWE-22"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-07-14T17:54:14Z"},"references":[{"type":"WEB","url":"https://github.com/k3s-io/k3s/security/advisories/GHSA-jxr7-mqhw-9p98"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54250"},{"type":"PACKAGE","url":"https://github.com/k3s-io/k3s"}],"affected":[{"package":{"name":"github.com/k3s-io/k3s","ecosystem":"Go","purl":"pkg:golang/github.com/k3s-io/k3s"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.35.0-rc1"},{"fixed":"1.35.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-jxr7-mqhw-9p98/GHSA-jxr7-mqhw-9p98.json"}},{"package":{"name":"github.com/k3s-io/k3s","ecosystem":"Go","purl":"pkg:golang/github.com/k3s-io/k3s"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.34.0-rc1"},{"fixed":"1.34.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-jxr7-mqhw-9p98/GHSA-jxr7-mqhw-9p98.json"}},{"package":{"name":"github.com/k3s-io/k3s","ecosystem":"Go","purl":"pkg:golang/github.com/k3s-io/k3s"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.33.10"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-jxr7-mqhw-9p98/GHSA-jxr7-mqhw-9p98.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:H"}]}