GPU VulnDB

Database/Container, Kubernetes & orchestration

kubectl cp on Windows: a malicious in-container tar writes files to arbitrary local paths

CVSS 6.5CVE-2026-19444Container, Kubernetes & orchestrationcurated

Impact

kubectl cp copying out of a container runs tar inside that container and unpacks its output locally. On Windows clients the unpack path can be traversed, so whoever controls the container image or its contents can write files anywhere the local user can write - including startup and profile locations - when an operator runs kubectl cp against that pod. The target is the cluster administrator's workstation, not the GPU node: the realistic chain is an operator pulling logs or artifacts out of a tenant pod and getting code placed on the machine that holds their kubeconfigs and cluster credentials. Linux and macOS kubectl clients are not affected.

Who can reach it

An attacker who controls the contents of a container (a tenant's own image, or a compromised workload) plus an operator on Windows who runs kubectl cp from that pod. Requires that operator action; privileges are bounded by the local Windows user.

What to do

Update kubectl on Windows workstations to the patched release from the Kubernetes security announcement; this is a client-side binary swap, no cluster or node change and no workload disruption. Until then, avoid kubectl cp out of untrusted pods from Windows, or run it from a Linux/macOS client or a throwaway jump host.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.