Threat Advisory

VictoriaMetrics vmrestore Path Traversal Escapes Restore Root

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A medium severity vulnerability affecting github.com/VictoriaMetrics/VictoriaMetrics versions >= 1.137.0, < 1.146.0 affecting github.com/VictoriaMetrics/VictoriaMetrics versions >= 1.123.0, < 1.136.12, CVE-2026-61625 with a CVSS score of 6.8, exists in the VictoriaMetrics vmrestore utility due to its failure to validate backup part path components before writing restored files to the local filesystem. This flaw allows an attacker who can provide or modify a backup source to craft object names containing '..' path components that cause vmrestore to write files outside the intended restore root, subject to the permissions of the vmrestore process. An attacker with write access to the backup storage used as the -src for vmrestore can create or overwrite arbitrary files on the host running vmrestore within the limits of the process's filesystem permissions. This vulnerability requires an attacker to have write access to the backup storage and is mitigated by following the principle of least privilege when granting access to backup storage buckets, which VictoriaMetrics' security model assumes.

RECOMMENDATION:

We recommend you to update VictoriaMetrics to version 1.146.0, 1.136.12, or 1.122.25.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A medium severity vulnerability affecting github.com/VictoriaMetrics/VictoriaMetrics versions >= 1.137.0, < 1.146.0 affecting github.com/VictoriaMetrics/VictoriaMetrics versions >= 1.123.0, < 1.136.12, CVE-2026-61625 with a CVSS score of 6.8, exists in the VictoriaMetrics vmrestore utility due to its failure to validate backup part path components before writing restored files to the local filesystem. This flaw allows an attacker who can provide or modify a backup source to craft object names containing '..' path components that cause vmrestore to write files outside the intended restore root, subject to the permissions of the vmrestore process. An attacker with write access to the backup storage used as the -src for vmrestore can create or overwrite arbitrary files on the host running vmrestore within the limits of the process's filesystem permissions. This vulnerability requires an attacker to have write access to the backup storage and is mitigated by following the principle of least privilege when granting access to backup storage buckets, which VictoriaMetrics' security model assumes.

RECOMMENDATION:

We recommend you to update VictoriaMetrics to version 1.146.0, 1.136.12, or 1.122.25.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu