| id: GO-2025-4110 |
| modules: |
| - module: kubevirt.io/kubevirt |
| versions: |
| - fixed: 1.6.1 |
| - introduced: 1.6.2 |
| - fixed: 1.7.0-rc.0 |
| vulnerable_at: 1.7.0-beta.0 |
| summary: KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt |
| cves: |
| - CVE-2025-64324 |
| ghsas: |
| - GHSA-46xp-26xh-hpqh |
| references: |
| - advisory: https://github.com/kubevirt/kubevirt/security/advisories/GHSA-46xp-26xh-hpqh |
| - web: https://github.com/kubevirt/kubevirt/commit/00d03e43e3bf03e563136695a4732b65ed42d764 |
| - web: https://github.com/kubevirt/kubevirt/commit/ff3b69b08b6b9c8d08d23735ca8d82455f790a69 |
| - web: https://github.com/kubevirt/kubevirt/pull/15037 |
| source: |
| id: GHSA-46xp-26xh-hpqh |
| created: 2025-11-17T13:00:35.381940893-05:00 |
| review_status: UNREVIEWED |