CVE-2025-62878 Security Alert: CRITICAL Vulnerability
Urgent: CVE-2025-62878 requires immediate attention.
· 3 min read
```htmlExecutive Summary
A critical vulnerability, CVE-2025-62878, has been identified in the rancher/local-path-provisioner affecting solo developers and small teams. This vulnerability allows a malicious user to exploit the parameters.pathPattern to create PersistentVolumes in arbitrary locations on the host node, potentially overwriting sensitive files or accessing unintended directories. The severity rating is critical (CVSS 10), necessitating immediate action.
Immediate Action
- Upgrade to patched versions:
v0.0.34or later. - Review your current
local-path-provisionerversion usingkubectl get pods -n -o jsonpath='{.items[*].spec.containers[*].image}'. - Isolate the affected service until you can apply the patch.
- Monitor your systems for any unauthorized file access or changes.
- Refer to the vendor advisory for further details.
Affected Versions
rancher/local-path-provisioner@<0.0.34vulnerable; upgrade tov0.0.34+
Resolution Guide
To mitigate the vulnerability, upgrade to a patched version of the local-path-provisioner. Use the following commands based on your environment:
kubectl apply -f https://github.com/rancher/local-path-provisioner/releases/download/v0.0.34/local-path-provisioner.yaml
For Docker users, you can pull the latest image:
docker pull rancher/local-path-provisioner:v0.0.34
There are no configuration hardening examples or feature flags applicable for this vulnerability, as the issue is resolved solely through version updates.
Detection & Verification
To check if you are using a vulnerable version, run:
kubectl get deployments -n -o jsonpath='{.items[*].spec.template.spec.containers[*].image}'
Verify the fix by ensuring the version reflects v0.0.34 or later. You can also check your PersistentVolume configurations to confirm that pathPattern does not allow path traversal.
Risk and Impact
If exploited, this vulnerability could allow an attacker to create PersistentVolumes that point to critical directories on the host, such as /etc, leading to potential data loss, unauthorized access, or system compromise. The blast radius includes any Kubernetes cluster using the affected local-path-provisioner, making it crucial to act swiftly.