Relative Path Traversal in PowerShell - CVE-2026-70337
Published: August 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to relative path traversal in Microsoft PowerShell Core when processing a server response from a malicious server. A remote attacker can host a malicious server and convince a user to connect to it to execute arbitrary code.
User interaction is required.