Answer in brief
CVE-2026-54250 records a Medium severity (CVSS 5.8) vulnerability in K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression. The current sources do not mark it as known exploited. The current feed maps github.com/k3s-io/k3s (go), github.com/k3s-io/k3s (go), github.com/k3s-io/k3s (go), github.com/k3s-io/k3s (go) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps github.com/k3s-io/k3s (go), github.com/k3s-io/k3s (go), github.com/k3s-io/k3s (go), github.com/k3s-io/k3s (go) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| github.com/k3s-io/k3sgo | >=1.35.0-rc1,<1.35.3 | 1.35.3 |
| github.com/k3s-io/k3sgo | >=1.34.0-rc1,<1.34.6 | 1.34.6 |
| github.com/k3s-io/k3sgo | <1.33.10 | 1.33.10 |
| github.com/k3s-io/k3sgo | >=1.35.0-rc1 <1.35.3 | 1.35.3 |
| github.com/k3s-io/k3sgo | >=1.34.0-rc1 <1.34.6 | 1.34.6 |
| github.com/k3s-io/k3sgo | >=0 <1.33.10 | 1.33.10 |
Published upstream
Jun 25, 2026
Evidence: source:osv:source_dates:source-dates:recordSource modified
Sep 10, 2026
Evidence: source:osv:source_dates:source-dates:recordFirst seen by HOL
Jun 25, 2026
#### Summary A path traversal vulnerability exists in K3s's etcd snapshot decompression functionality. Zip files containing archive members with maliciously crafted names (e.g., `../../../../etc/password`) can be written to arbitrary locations on the filesystem when an administrator restores the archive as a compressed etcd snapshot. #### Mitigations * Enable golang's built-in [insecure path protections](https://pkg.go.dev/archive/zip#NewReader) when restoring snapshots by setting the`GODEBUG` environment variable: ```bash GODEBUG=zipinsecurepath=0 k3s server --cluster-reset --cluster-reset-restore-path=/path/to/snapshot.zip ``` * Manually extract the snapshot from the zip archive before restoring it. If the snapshot to be restored does not end with `.zip`, the vulnerable extraction code will not be executed. #### Additional Notes Administrators should be aware of the cautions noted in the "Security" section of the documentation on [Restoring Snapshots](https://docs.k3s.io/cli/etcd-snapshot#security).
Quoted source text, attributed separately from HOL analysis.