Path traversal in Podman - CVE-2025-11395
Published: September 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to overwrite attacker-chosen files and modify their attributes.
The vulnerability exists due to improper archive extraction in storage/pkg/archive when extracting a maliciously crafted tar archive. A remote attacker can provide a maliciously crafted tar archive to overwrite attacker-chosen files and modify their attributes.
User interaction is required to extract the crafted archive.