{"id":"CVE-2026-32725","summary":"SciTokens C++: Relative Path Traversal Vulnerability","details":"SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass when processing path-based scopes in tokens. The library normalizes the scope path from the token before authorization and collapses \"..\" path components instead of rejecting them. As a result, an attacker can use parent-directory traversal in the scope claim to broaden the effective authorization beyond the intended directory. This issue has been patched in version 1.4.1.","aliases":["GHSA-rqcx-mc9w-pjxp"],"modified":"2026-08-12T15:32:26.263889Z","published":"2026-03-31T17:01:46.776Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-23"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32725.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32725.json"},{"type":"ADVISORY","url":"https://github.com/scitokens/scitokens-cpp/security/advisories/GHSA-rqcx-mc9w-pjxp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32725"},{"type":"FIX","url":"https://github.com/scitokens/scitokens-cpp/commit/7951ed809967d88c00c20de414b1ff74df8c3e08"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/scitokens/scitokens-cpp","events":[{"introduced":"0"},{"fixed":"fffcab6b9a80105a671ac039772ba81efe73e7e3"},{"fixed":"7951ed809967d88c00c20de414b1ff74df8c3e08"}],"database_specific":{"cpe":"cpe:2.3:a:scitokens:scitokens_cpp_library:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.4.1"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v1.4.0","v1.3.0","v.1.3.0-rc0","v1.2.0","v1.1.3","v1.1.2","v1.1.1","v1.1.0","v1.0.2","v0.7.1","v0.7.0","v0.6.3","v0.6.2","v0.6.1","v0.6.0","v0.5.1","v0.5.0","v0.3.4","v0.3.5","v0.3.3","v","v0.3.2","v0.3.1","v0.3.0","v0.2.0","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-32725.json","vanir_signatures_modified":"2026-08-12T15:32:26Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"114373754308404994386487506083326982335","length":1961},"id":"CVE-2026-32725-16813168","signature_type":"Function","signature_version":"v1","source":"https://github.com/scitokens/scitokens-cpp/commit/7951ed809967d88c00c20de414b1ff74df8c3e08","target":{"file":"src/scitokens_internal.cpp","function":"scitokens::Enforcer::scope_validator"}},{"signature_version":"v1","source":"https://github.com/scitokens/scitokens-cpp/commit/7951ed809967d88c00c20de414b1ff74df8c3e08","target":{"file":"src/scitokens_internal.cpp"},"deprecated":false,"digest":{"line_hashes":["287380959812084164866198263980111908944","125305705647164214597094911311009461852","47834424582843579889526340777241291166","90825064717826589204887566121236740240","244419171305235120484112210993575192501","53535272776844004058058137994433939254","338887205321118828573314793477526868446","267685471469062729337917053404013544171","7223480695584261335320850106564769635","73639859831779728519655974170866361187","331938783273713778430129325239461320827","9173043784232848639909615837382931456","265961603437822894320619417896334385726","191801885600154290790839151999701357115","6696842953503876800146082481653522168","271142712065282462817583389660095598482","147509157642943216596049050638048767315","56977922654007903344845882373206944238","141590355391451579121415695504388568849","27910058349441269004604065367096837277","308211188440469518023752437835598163127","101959876960327385993759654702256778021","181029955074579559509242083301972303551","168809173563883832126329846286823848247","104558846724609165065198697661051723299","40408618947713847836970581578786280598","62052748072749066613227931236333892686","130580896055094365179281698859615783298","233862073546409500201135229367082879077","304135058610660299043956982101812837046","252604093066019614078677797973923488078","8004679280101568436248289617421772375","320908077028609814069030573452956359064","2840374984355414358269149593647494190","268534507115766307195870513231234597031","190789545784742455541952304350660604004","45835481886593324551265984120394737971","296993931303692723268801504691333464120","333263373355096770734442635924414142725"],"threshold":0.9},"id":"CVE-2026-32725-6d89271c","signature_type":"Line"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/scitokens/scitokens-cpp/commit/7951ed809967d88c00c20de414b1ff74df8c3e08","target":{"file":"test/main.cpp"},"deprecated":false,"digest":{"line_hashes":["70675864853198927462867307192072441711","300959398191096246495785325624423110428","179126307303383970185612483052123876233"],"threshold":0.9},"id":"CVE-2026-32725-718e6106"},{"digest":{"function_hash":"306235316994512207497844610584114447907","length":950},"id":"CVE-2026-32725-92a82f57","signature_type":"Function","signature_version":"v1","source":"https://github.com/scitokens/scitokens-cpp/commit/7951ed809967d88c00c20de414b1ff74df8c3e08","target":{"function":"normalize_absolute_path","file":"src/scitokens_internal.cpp"},"deprecated":false}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"}]}