managementServer.CreateSchematic (internal/backend/grpc/schematics.go) passes the caller-controlled TalosVersion field directly to imageFactoryClient.OverlaysVersions, which embeds it verbatim into a fmt.Sprintf("/version/%s/overlays/official", talosVersion) path template. url.URL.JoinPath resolves any ../ sequences in that path, allowing an authenticated Operator to rewrite the URL path and force Omni to issue HTTP GET requests to unintended paths on the configured image-factory server. Error body content from those unintended endpoints is returned to the caller.
CreateSchematic API endpoint.role.Operator is required, which has administrative capabilities on Omni.../ prefixes in talosVersion, the attacker can reach any path hierarchy on the image-factory host.This vulnerability was discovered and reported by bugbunny.ai.
{
"cwe_ids": [
"CWE-20",
"CWE-209",
"CWE-22",
"CWE-441",
"CWE-918"
],
"github_reviewed": true,
"github_reviewed_at": "2026-06-05T15:25:58Z",
"nvd_published_at": null,
"severity": "LOW"
}