A path traversal vulnerability exists in K3s's etcd snapshot decompression functionality. Zip files containing archive members with maliciously crafted names (e.g., ../../../../etc/password) can be written to arbitrary locations on the filesystem when an administrator restores the archive as a compressed etcd snapshot.
GODEBUG environment variable:
GODEBUG=zipinsecurepath=0 k3s server --cluster-reset --cluster-reset-restore-path=/path/to/snapshot.zip
.zip, the vulnerable extraction code will not be executed.Administrators should be aware of the cautions noted in the "Security" section of the documentation on Restoring Snapshots.
{
"cwe_ids": [
"CWE-22"
],
"github_reviewed": true,
"github_reviewed_at": "2026-07-14T17:54:14Z",
"nvd_published_at": "2026-06-25T19:16:41Z",
"severity": "MODERATE"
}