{"id":"CVE-2021-20206","aliases":["GHSA-xjqr-g762-pxwp","GO-2022-0230"],"url":"https://o3.security/vulnerability/CVE-2021-20206","summary":"containernetworking/cni improper limitation of path name","details":"An improper limitation of path name flaw was found in containernetworking/cni in versions before 0.8.1. When specifying the plugin to load in the 'type' field in the network configuration, it is possible to use special elements such as \"../\" separators to reference binaries elsewhere on the system. This flaw allows an attacker to execute other existing binaries other than the cni plugins/types, such as 'reboot'. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.","published":"2021-03-26T22:15:12.617Z","modified":"2026-07-09T00:07:00.470453Z","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.01525,"percentile":0.7231,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/containernetworking/cni","fixedVersion":"0.8.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMCONTAINERNETWORKINGCNIPKGINVOKE-1070549"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1919391"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T00:07:00.470453Z"}}