Path traversal in Harbor - #VU153944
Published: October 7, 2026 / Updated: October 8, 2026
Vulnerability details
The vulnerability allows a remote user to disclose image metadata and modify or delete tags and manifests across projects without the required repository permissions.
The vulnerability exists due to path traversal in the registry manifest endpoints when checking permissions against raw request paths before resolving parent-directory segments. A remote user can send crafted registry requests containing parent-directory segments to disclose image metadata and modify or delete tags and manifests across projects without the required repository permissions.
Changing or deleting content requires push access to at least one project. Unauthenticated manifest reads are also possible when the instance has at least one public project.