CVE-2026-61625 | VictoriaMetrics up to 1.122.24/1.136.11/1.145.x Restore restore.go path traversal

SecurityVulns

A vulnerability was found in VictoriaMetrics up to 1.122.24/1.136.11/1.145.x. It has been declared as problematic. The affected element is an unknown function of the file lib/backup/actions/restore.go of the component Restore. Executing a manipulation can lead to path traversal.

The identification of this vulnerability is CVE-2026-61625. The attack may be launched remotely. There is no exploit available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More