migration-planner Vulnerability: Improper Input Sanitization Risk
- Severity
- HIGH
- Affected component
- github.com/kubev2v/migration-planner (go)
- Affected versions
- < 0.13.5 or < 0.13.5 or < 0.13.5
- Patched version
- Not yet available
An early warning has been issued for a vulnerability in migration-planner that could allow a remote authenticated attacker to execute malicious SQL commands via a specially crafted RVTools .xlsx file.
What happened
An early warning has been issued regarding a vulnerability in the migration-planner component. This flaw, tracked as GHSA-VF2H-7X3W-97FR, allows a remote authenticated attacker to exploit improper input sanitization by uploading a specially crafted RVTools .xlsx file. When cluster names are processed, malicious SQL embedded within a spreadsheet cell is executed. This vulnerability affects versions of migration-planner prior to 0.13.5.
The vulnerability was first flagged on June 10, 2026. It is currently under investigation and has not been reported as exploited in the wild. Users of affected versions are advised to take immediate action to mitigate potential risks.
What to do about it
- Upgrade to the latest version of migration-planner to mitigate the risk of this vulnerability.
- Review any uploaded files for potential malicious content to ensure they do not contain malicious SQL commands.
- Monitor the primary sources for updates on this vulnerability and any official fixes that may be released.
How 0Day would have caught this
github.com/kubev2v/migration-planner is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you are using a version of migration-planner prior to 0.13.5.
What should I do right now?
Upgrade to the latest version of migration-planner and review any uploaded files for potential malicious content.
Has an official fix been released?
No official fix has been published yet. Monitor the sources for updates.