GHSA-c66c-vq6w-fvh5

Suggest an improvement
Source
https://github.com/advisories/GHSA-c66c-vq6w-fvh5
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-c66c-vq6w-fvh5/GHSA-c66c-vq6w-fvh5.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-c66c-vq6w-fvh5
Aliases
Published
2026-06-05T15:25:58Z
Modified
2026-06-25T19:56:18Z
Severity
  • 2.7 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic
Details

Summary

managementServer.CreateSchematic (internal/backend/grpc/schematics.go) passes the caller-controlled TalosVersion field directly to imageFactoryClient.OverlaysVersions, which embeds it verbatim into a fmt.Sprintf("/version/%s/overlays/official", talosVersion) path template. url.URL.JoinPath resolves any ../ sequences in that path, allowing an authenticated Operator to rewrite the URL path and force Omni to issue HTTP GET requests to unintended paths on the configured image-factory server. Error body content from those unintended endpoints is returned to the caller.

Severity

  • Attack Vector: Network: exploited via the gRPC CreateSchematic API endpoint.
  • Attack Complexity: Low: once the attacker holds an Operator credential and has identified a media ID with an overlay, exploitation is a single API call.
  • Privileges Required: High: role.Operator is required, which has administrative capabilities on Omni.
  • User Interaction: None.
  • Scope: Unchanged: the traversal is constrained to the configured image-factory host; the attacker cannot redirect Omni to an arbitrary external server.
  • Confidentiality Impact: Low: error body content from unintended image-factory endpoints is reflected back to the operator, potentially leaking server-internal information.
  • Integrity Impact: None: only HTTP GET requests are issued; no write operations are performed.
  • Availability Impact: None.

Impact

  • Same-host path traversal: An authenticated Operator can force Omni to issue GET requests to arbitrary URL paths on the configured image-factory server, bypassing the intended versioned overlay API structure.
  • Error-body disclosure: HTTP error responses from unintended image-factory endpoints are reflected back to the operator, potentially leaking server-internal diagnostics or sensitive path content.
  • Internal network probing: In deployments using a private image-factory instance on an internal network, the attacker can probe endpoint existence and partial responses through error-text differences.
  • Depth control: By varying the number of ../ prefixes in talosVersion, the attacker can reach any path hierarchy on the image-factory host.

Credit

This vulnerability was discovered and reported by bugbunny.ai.

Database specific
{
    "cwe_ids":  [
        "CWE-20",
        "CWE-209",
        "CWE-22",
        "CWE-441",
        "CWE-918"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-06-05T15:25:58Z",
    "nvd_published_at":  null,
    "severity":  "LOW"
}
References

Affected packages

Go / github.com/siderolabs/omni

Package

Name
github.com/siderolabs/omni
View open source insights on deps.dev
Purl
pkg:golang/github.com/siderolabs/omni

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.6.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-c66c-vq6w-fvh5/GHSA-c66c-vq6w-fvh5.json"

Go / github.com/siderolabs/omni

Package

Name
github.com/siderolabs/omni
View open source insights on deps.dev
Purl
pkg:golang/github.com/siderolabs/omni

Affected ranges

Type
SEMVER
Events
Introduced
1.7.0
Fixed
1.7.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-c66c-vq6w-fvh5/GHSA-c66c-vq6w-fvh5.json"