Windows kubectl cp path traversal lets containers write arbitrary files
CVE-2026-19444 is a medium-severity flaw in several kubectl release lines that only affects clients running on Windows.
A malicious tar binary inside a container can trick Windows users of kubectl cp into writing files anywhere the local account can reach, Kubernetes has disclosed as CVE-2026-19444.
The issue is rated medium (CVSS 6.5). It matters for anyone who copies files from containers they do not fully control onto a Windows workstation: the client trusts the archive stream from the pod, and a crafted path can escape the intended destination. Linux and macOS kubectl clients are not affected. Impact is capped by the permissions of the user running kubectl, not by cluster admin rights.
Affected clients are kubectl 1.34.0 through 1.34.11, 1.35.0 through 1.35.8, and 1.36.0 through 1.36.4. Fixes ship in 1.34.12, 1.35.9, and 1.36.5 and later. Until operators upgrade, the practical mitigation is to avoid kubectl cp from untrusted containers on Windows, or to copy only from images and workloads they trust.
Moriel Harush reported the vulnerability. The Kubernetes Security Response Committee coordinated the fix.