Executive brief
The Assisted Migration Agent is a tool used to migrate virtual machines and infrastructure configurations between systems. An unauthenticated attacker on the same local network can exploit a path traversal vulnerability in how the agent extracts gzipped tarballs, allowing them to write arbitrary files to the system and execute malicious code with the agent's privileges. This could lead to complete compromise of the virtualization infrastructure and exfiltration of sensitive vCenter credentials.
Technical details
The vulnerability resides in the PUT /inspector/vddk endpoint's extractTarGz() function (internal/services/vddk.go:173), which validates extracted paths using only lexical checks (filepath.Clean + HasPrefix) without resolving symlinks already present on disk. An attacker can craft a tarball that first creates a symlink (e.g., a/x → ..), which passes validation, then writes files via that symlink (a/x/evil.sh) that actually land outside the intended extraction directory. This allows arbitrary file writes as UID 1001, including config files in /var/lib/agent/ and executable code in /app/.cache, enabling persistent code execution with vCenter admin credentials. The fix, released in version 0.16.0, resolves parent directory symlinks using filepath.EvalSymlinks before file creation and re-validates that the resolved path remains within the extraction directory, while preserving support for legitimate internal .so version symlinks in VDDK tarballs.
Affected products
- kubev2v Assisted Migration Agent < 0.16.0
Timeline
- 2026-06-10: disclosed
- 2026-06-07: patched: Fix merged in PR #256; patch released in version 0.16.0