CVE-2025-62878 Security Alert: CRITICAL Vulnerability

Urgent: CVE-2025-62878 requires immediate attention.

· 3 min read

```html

Executive Summary

A critical vulnerability, CVE-2025-62878, has been identified in the rancher/local-path-provisioner affecting solo developers and small teams. This vulnerability allows a malicious user to exploit the parameters.pathPattern to create PersistentVolumes in arbitrary locations on the host node, potentially overwriting sensitive files or accessing unintended directories. The severity rating is critical (CVSS 10), necessitating immediate action.

Immediate Action

  • Upgrade to patched versions: v0.0.34 or later.
  • Review your current local-path-provisioner version using kubectl get pods -n -o jsonpath='{.items[*].spec.containers[*].image}'.
  • Isolate the affected service until you can apply the patch.
  • Monitor your systems for any unauthorized file access or changes.
  • Refer to the vendor advisory for further details.

Affected Versions

  • rancher/local-path-provisioner@<0.0.34 vulnerable; upgrade to v0.0.34+

Resolution Guide

To mitigate the vulnerability, upgrade to a patched version of the local-path-provisioner. Use the following commands based on your environment:

kubectl apply -f https://github.com/rancher/local-path-provisioner/releases/download/v0.0.34/local-path-provisioner.yaml

For Docker users, you can pull the latest image:

docker pull rancher/local-path-provisioner:v0.0.34

There are no configuration hardening examples or feature flags applicable for this vulnerability, as the issue is resolved solely through version updates.

Detection & Verification

To check if you are using a vulnerable version, run:

kubectl get deployments -n  -o jsonpath='{.items[*].spec.template.spec.containers[*].image}'

Verify the fix by ensuring the version reflects v0.0.34 or later. You can also check your PersistentVolume configurations to confirm that pathPattern does not allow path traversal.

Risk and Impact

If exploited, this vulnerability could allow an attacker to create PersistentVolumes that point to critical directories on the host, such as /etc, leading to potential data loss, unauthorized access, or system compromise. The blast radius includes any Kubernetes cluster using the affected local-path-provisioner, making it crucial to act swiftly.

```

Keep reading