{"schema_version":"1.7.3","id":"GHSA-r492-hjgh-c9gw","published":"2026-02-27T16:03:54Z","modified":"2026-03-23T04:56:19.128798525Z","aliases":["CVE-2026-27969","GO-2026-4570"],"summary":"Vitess users with backup storage access can write to arbitrary file paths on restore","details":"### Impact\n\nAnyone with read/write access to the backup storage location (e.g. an S3 bucket) can manipulate backup manifest files so that files in the manifest — which may be files that they have also added to the manifest and backup contents — are written to any accessible location on restore. This is a common [Path Traversal](https://owasp.org/www-community/attacks/Path_Traversal) security issue. This can be used to provide that attacker with unintended/unauthorized access to the production deployment environment — allowing them to access information available in that environment as well as run any additional arbitrary commands there.\n\n### Patches\n\nv23.0.3 and v22.0.4\n\n### Resources\n\nhttps://github.com/vitessio/vitess/pull/19470","affected":[{"package":{"name":"vitess.io/vitess","ecosystem":"Go","purl":"pkg:golang/vitess.io/vitess"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.23.0-rc1"},{"fixed":"0.23.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-r492-hjgh-c9gw/GHSA-r492-hjgh-c9gw.json"}},{"package":{"name":"vitess.io/vitess","ecosystem":"Go","purl":"pkg:golang/vitess.io/vitess"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.22.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-r492-hjgh-c9gw/GHSA-r492-hjgh-c9gw.json"}}],"references":[{"type":"WEB","url":"https://github.com/vitessio/vitess/security/advisories/GHSA-r492-hjgh-c9gw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27969"},{"type":"WEB","url":"https://github.com/vitessio/vitess/pull/19470"},{"type":"WEB","url":"https://github.com/vitessio/vitess/commit/c565cab615bc962bda061dcd645aa7506c59ca4a"},{"type":"PACKAGE","url":"https://github.com/vitessio/vitess"},{"type":"WEB","url":"https://owasp.org/www-community/attacks/Path_Traversal"}],"database_specific":{"cwe_ids":["CWE-22"],"github_reviewed":true,"github_reviewed_at":"2026-02-27T16:03:54Z","nvd_published_at":"2026-02-26T02:16:24Z","severity":"CRITICAL"},"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:L/SC:L/SI:H/SA:H"}]}