GO · JUNE 2026 · EARLY WARNING

migration-planner Vulnerability: Improper Input Sanitization Risk

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
github.com/kubev2v/migration-planner (go)
Affected versions
< 0.13.5 or < 0.13.5 or < 0.13.5
Patched version
Not yet available
GHSA-VF2H-7X3W-97FR

An early warning has been issued for a vulnerability in migration-planner that could allow a remote authenticated attacker to execute malicious SQL commands via a specially crafted RVTools .xlsx file.

What happened

An early warning has been issued regarding a vulnerability in the migration-planner component. This flaw, tracked as GHSA-VF2H-7X3W-97FR, allows a remote authenticated attacker to exploit improper input sanitization by uploading a specially crafted RVTools .xlsx file. When cluster names are processed, malicious SQL embedded within a spreadsheet cell is executed. This vulnerability affects versions of migration-planner prior to 0.13.5.

The vulnerability was first flagged on June 10, 2026. It is currently under investigation and has not been reported as exploited in the wild. Users of affected versions are advised to take immediate action to mitigate potential risks.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If github.com/kubev2v/migration-planner is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if you are using a version of migration-planner prior to 0.13.5.

What should I do right now?

Upgrade to the latest version of migration-planner and review any uploaded files for potential malicious content.

Has an official fix been released?

No official fix has been published yet. Monitor the sources for updates.

Sources

Join the 0Day waitlist →

← Back to all threats