Posted by Vyom Yadav on Sep 28 Hello Kubernetes Community, A security issue was discovered in Kubernetes where a malicious tar binary in a container may be able to write files to arbitrary paths on the local machine of a user running kubectl cp on Windows, limited only by the permissions of the local user. This issue has been rated *Medium* (CVSS calculator: https://www.first.org/cvss/calculator/3.1) (score 6.5), and assigned *CVE-2026-19444*. *Am I vulnerable?* You are...
[kubernetes] CVE-2026-19444: kubectl cp path traversal on Windows allows arbitrary file writes
About this summary. This is a short, independently written summary of an article first published by oss-security. Cyber Security News did not report or verify the underlying story. Read the original: https://seclists.org/oss-sec/2026/q3/960
Source attribution: headline and facts are from oss-security (seclists.org). Summary method: excerpt of the source description. See our source attribution policy.



