天下漏洞,尽知其名
MEDIUM 重点关注

CVE-2026-19444 Kubernetes kubectl 路径遍历漏洞

影响攻击者可向用户本地机器任意路径写入文件

AI 研判

CVE-2026-19444 是 Kubernetes kubectl 客户端在 Windows 平台上的路径穿越漏洞。kubectl cp 从容器复制文件时会在容器内运行 tar 打包并在本地解包,若容器内 tar 被恶意替换,可产生异常输出导致本地任意路径写入。该问题仅影响在 Windows 上运行的 kubectl 客户端。

影响范围

Kubernetes kubectl

仅影响在 Windows 上运行的 kubectl 客户端,具体受影响版本范围暂无公开信息。

漏洞详情

漏洞类型为路径穿越(目录穿越)。kubectl cp 从容器向本地复制文件时,依赖容器内的 tar 二进制生成归档,再在本地解包;当容器内 tar 被攻击者控制并输出恶意构造的路径时,本地解包过程未充分校验路径,导致文件被写到预期目录之外。攻击者需能控制容器内容(如镜像或容器内文件)。

利用条件与风险

利用前提是用户使用 Windows 版 kubectl 执行 kubectl cp 从恶意容器复制文件,且攻击者已控制容器内容;写入范围受本地用户权限限制,实战中可覆盖用户可写文件,风险中等。

修复建议

建议关注 Kubernetes 官方针对该 CVE 发布的修复版本并及时升级 kubectl;临时缓解措施包括避免对不可信容器使用 kubectl cp,或在复制前确认容器内 tar 未被篡改,具体方案以官方公告为准。

原始情报

A path traversal vulnerability was discovered in the Kubernetes kubectl client’s kubectl cp command on Windows. When copying files from a container, kubectl runs tar inside the container to build a tar archive, transfers it over the network, and unpacks it on the local machine. If the tar binary in the container is malicious, it can execute arbitrary code and emit unexpected output, allowing an attacker who controls container contents to write files to arbitrary paths on the user’s local machine when kubectl cp is invoked, limited only by the system permissions of the local user. This issue only affects kubectl clients running on Windows.