PatchSiren

VictoriaMetrics CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM VictoriaMetrics CVE published 2026-08-20

CVE-2026-61625

PatchSiren debrief for CVE-2026-61625: VictoriaMetrics vmrestore path traversal vulnerability allows an attacker to create or overwrite files outside the intended restore root. Operators and administrators of VictoriaMetrics systems should assess exposure and apply updates to prevent potential path traversal attacks. The issue is caused by a lack of validation of backup part path components before using l [truncated]