CVE-2025-9566
There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful attack, the attacker can only control the target file to be overwritten but not the content to be written into the file. Binary-Affected: podman Upstream-version-introduced: v4.0.0 Upstream-version-fixed: v5.6.1
Scoring
- Severity
- HIGH
- CVSS base score
- 8.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
- EPSS probability
- 1.08%
- CWE
- CWE-22
- Published
- 2025-09-05
- Last modified
- 2026-09-10
Affected products
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
- Red Hat Red Hat Enterprise Linux 8.6 Telecommunications Update Service
- Red Hat Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
- Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service
- Red Hat Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
Weakness type
Related vulnerabilities
- CVE-2026-85706 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
- CVE-2026-78657 — SigmaForms Pro <= 1.4.11 - Unauthenticated Arbitrary File Deletion via Path Traversal in File Upload Field
- CVE-2026-61560 — @zereight/mcp-gitlab's unauthenticated arbitrary file read via `upload_markdown` enables PAT exfiltration and full account takeover
- CVE-2026-82100 — DataStage on Cloud Pak for Data has several vulnerabilities due to open source software
- CVE-2026-82954 — Dokploy Settings application.ts writeTraefikConfigInPath path traversal
- CVE-2026-85661 — excel-mcp-server 0.1.8 Arbitrary File Read/Write via stdio mode
- CVE-2026-89040 — Tencent Mass Service Engine in Cluster (MSEC) path traversal
- CVE-2026-88069 — Path traversal in Pandora archive extractor allows arbitrary file writes outside the extraction directory in pandora analysis