CVE-2026-12701 is a path traversal vulnerability in pulpcore affecting FilesystemExport operations. The flaw is in the relative_path_validator function, which validates that a content path does not begin with "/" but does not reject embedded directory traversal sequences such as "../" elsewhere in the path. An authenticated administrator can supply a crafted relative_path that escapes the intended export directory. Because the exported content originates from an uploaded artifact, the attacker also controls the file data written through the export operation. This results in arbitrary file write to locations writable by the Pulp service user and can enable compromise of the Pulp service or further host-level exploitation depending on filesystem permissions and confinement controls.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical path traversal vulnerability in pulpcore's relative_path_validator that can allow an authenticated administrator to perform arbitrary file writes outside the intended export directory during FilesystemExport operations, potentially leading to service compromise or further system exploitation.
A directory traversal vulnerability in pulpcore's FilesystemExport feature that allows bypass of relative_path_validator checks, fixed in the Red Hat Satellite update.
A directory traversal vulnerability in pulpcore's FilesystemExport relative_path_validator bypass.
A directory traversal vulnerability in pulpcore FilesystemExport that bypasses relative_path_validator protections.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.