{"id":"CVE-2025-3047","summary":"Path Traversal in AWS SAM CLI allows file copy to build container","details":"When running the AWS Serverless Application Model Command Line Interface (SAM CLI) build process with Docker and symlinks are included in the build files, the container environment allows a user to access privileged files on the host by leveraging the elevated permissions granted to the tool. A user could leverage the elevated permissions to access restricted files via symlinks and copy them to a more permissive location on the container. \n\nUsers should upgrade to v1.133.0 or newer and ensure any forked or derivative code is patched to incorporate the new fixes.","aliases":["GHSA-px37-jpqx-97q9","PYSEC-2026-1207"],"modified":"2026-08-12T03:51:17.636330346Z","published":"2025-03-31T15:21:11.290Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/3xxx/CVE-2025-3047.json","cna_assigner":"AMZN","cwe_ids":["CWE-61"]},"references":[{"type":"ADVISORY","url":"https://aws.amazon.com/security/security-bulletins/AWS-2025-008/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/3xxx/CVE-2025-3047.json"},{"type":"ADVISORY","url":"https://github.com/aws/aws-sam-cli/security/advisories/GHSA-px37-jpqx-97q9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-3047"},{"type":"FIX","url":"https://github.com/aws/aws-sam-cli/releases/tag/v1.134.0"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/aws/aws-sam-cli","events":[{"introduced":"2597047b75eedbef75f4352be801dd2327fec63b"},{"fixed":"bde031e2421e05183f02f81cf2b8c0a759046b8f"}],"database_specific":{"extracted_events":[{"introduced":"1.98.0"},{"fixed":"1.133.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v1.133.0","v1.132.0","v1.131.0","v1.130.0","v1.129.0","v1.128.0","v1.127.0","v1.126.0","v1.125.0","v1.124.0","v1.123.0","v1.122.0","v1.121.0","v1.120.0","v1.119.0","v1.118.0","v1.117.0","v1.116.0","v1.115.0","v1.114.0","v1.113.0","v1.112.0","v1.111.0","v1.110.0","v1.109.0","v1.108.0","v1.107.0","v1.106.0","v1.105.0","v1.104.0","v1.103.0","v1.102.0","v1.101.0","v1.100.0","v1.99.0","v1.98.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-3047.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}