| id: GO-2026-6231 |
| modules: |
| - module: github.com/kubev2v/assisted-migration-agent |
| versions: |
| - fixed: 0.16.0 |
| vulnerable_at: 0.12.0 |
| summary: |- |
| Assisted Migration Agent: Path traversal in gzipped tarball handling enables |
| arbitrary file write and remote code execution in github.com/kubev2v/assisted-migration-agent |
| cves: |
| - CVE-2026-53476 |
| ghsas: |
| - GHSA-7j4w-x8x8-5mvg |
| references: |
| - advisory: https://github.com/advisories/GHSA-7j4w-x8x8-5mvg |
| - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-53476 |
| - fix: https://github.com/kubev2v/assisted-migration-agent/commit/bcae0438ad8386321a300413d71c982a11b7b5b7 |
| - fix: https://github.com/kubev2v/assisted-migration-agent/pull/256 |
| - web: https://access.redhat.com/security/cve/CVE-2026-53476 |
| - web: https://bugzilla.redhat.com/show_bug.cgi?id=2487233 |
| source: |
| id: GHSA-7j4w-x8x8-5mvg |
| created: 2026-08-17T22:52:38.759771-04:00 |
| review_status: UNREVIEWED |