Database/Container, Kubernetes & orchestration
kubectl cp on Windows: a malicious in-container tar writes files to arbitrary local paths
Impact
kubectl cp copying out of a container runs tar inside that container and unpacks its output locally. On Windows clients the unpack path can be traversed, so whoever controls the container image or its contents can write files anywhere the local user can write - including startup and profile locations - when an operator runs kubectl cp against that pod. The target is the cluster administrator's workstation, not the GPU node: the realistic chain is an operator pulling logs or artifacts out of a tenant pod and getting code placed on the machine that holds their kubeconfigs and cluster credentials. Linux and macOS kubectl clients are not affected.
Who can reach it
An attacker who controls the contents of a container (a tenant's own image, or a compromised workload) plus an operator on Windows who runs kubectl cp from that pod. Requires that operator action; privileges are bounded by the local Windows user.
What to do
Update kubectl on Windows workstations to the patched release from the Kubernetes security announcement; this is a client-side binary swap, no cluster or node change and no workload disruption. Until then, avoid kubectl cp out of untrusted pods from Windows, or run it from a Linux/macOS client or a throwaway jump host.
References
Related entries
- ingress-nginx: Admission controller denial of serviceCVE-2026-24514 · ingress-nginxMedium
- CSI Driver NFS: Path traversal via `subDir` lets a tenant delete unintended directories on the shared NFS serverCVE-2026-3864 · CSI Driver NFSMedium
- CSI Driver SMB: Same `subDir` path traversal against a shared SMB serverCVE-2026-3865 · CSI Driver SMBMedium
- Contour: fallback certificate with JWT providers lets SNI-less requests skip JWT verificationCVE-2026-50149 · Projectcontour Contour ingress controller (HTTPProxy fallback certificate + jwtProviders)Medium
- Envoy Gateway: unbounded gzip decompression of a tenant-supplied Wasm URL OOM-kills the shared controllerCVE-2026-53716 · Envoy Gateway control plane (Wasm HTTP fetcher, getFileFromGZ)Medium
- Envoy Gateway: tar header size is trusted before validation, so one OCI Wasm layer crash-loops the controllerCVE-2026-53717 · Envoy Gateway control plane (OCI Wasm image fetcher, extractWasmPluginBinary)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.