GO · JUNE 2026 · EARLY WARNING

migration-planner Package Vulnerability: Broken Access Control

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
github.com/kubev2v/migration-planner (go)
Affected versions
< 0.13.5
Patched version
Not yet available
GHSA-V5M8-5455-QW2X

An improper access control vulnerability in the migration-planner package could allow an authenticated attacker to obtain presigned S3 URLs for other users' OVA images.

What happened

An early warning has been issued regarding a vulnerability in the migration-planner package. The vulnerability, tracked as GHSA-V5M8-5455-QW2X, involves improper access control in the /api/v1/sources/{id}/image-url endpoint. This flaw allows an authenticated attacker to bypass ownership checks and obtain presigned S3 URLs for Open Virtual Appliance (OVA) images belonging to other users. This could potentially lead to unauthorized access and modification of the victim's source.

The affected component is github.com/kubev2v/migration-planner (go) for versions less than 0.13.5. The vulnerability has not been reported as exploited in the wild. Users of this package should assess their exposure based on their current version and the provided details.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If github.com/kubev2v/migration-planner is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if you are using github.com/kubev2v/migration-planner (go) version less than 0.13.5.

What should I do right now?

Monitor for updates from the maintainers and apply patches as they become available. Ensure your version is 0.13.5 or later.

Has this been exploited in the wild?

The vulnerability has not been reported as exploited in the wild.

Sources

Join the 0Day waitlist →

← Back to all threats