Pulpcore Path Traversal Vulnerability: Critical CVE-2026-12701 Alert
An early warning has been issued for a critical path traversal vulnerability in pulpcore, tracked as CVE-2026-12701. This vulnerability could allow an authenticated administrator to perform arbitrary file writes, potentially leading to service compromise.
What happened
A path traversal vulnerability has been identified in the pulpcore package, affecting versions from 0 to 3.56.0 and various beta, release candidate, and post versions. The vulnerability lies in the relative_path_validator function, which fails to properly block directory traversal sequences. This could allow an authenticated administrator to write arbitrary files to any location writable by the Pulp service user, potentially leading to service compromise or further system exploitation.
The vulnerability has been assigned a CVSS score of 9.0, indicating a critical severity level. It is recommended to upgrade to a patched version of pulpcore as soon as it becomes available. For more detailed information, consult the primary sources linked in the incident data.
How 0Day mitigates this
pulpcore is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.