{"id":"GHSA-r5jh-q2mw-gcx4","summary":"Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape","details":"`SanitizeFilePath` in `pkg/utils/utils.go` validated that a path stayed under a safe directory by calling `strings.HasPrefix(path, safedir)`. This is a lexical check, not a directory boundary check: `/packages-extra/evil` starts with\n`/packages`, so it passed. The function did not enforce a path-separator boundary, so any sibling directory whose name began with the safe-directory string was accepted.\n\nCallers included the builder's `Clean` handler (`pkg/builder/builder.go:208`) and the fetcher's `Fetch` / `Upload` handlers (`pkg/fetcher/fetcher.go`). A tenant who could pre-create or control a sibling directory under the fetcher /\nbuilder's shared volume could induce a write or read outside the intended safe directory.\n\n### Affected\n\n- Project: `github.com/fission/fission`\n- Versions: all versions through v1.24.0 with `SanitizeFilePath` in the tree\n- Audited commit: `647c141`\n- Component: `pkg/utils/utils.go:SanitizeFilePath`\n- Callers: `pkg/builder/builder.go:157,164,208`, `pkg/fetcher/fetcher.go:296,311,450,496,565,571`\n- Configuration: default; requires a sibling directory to the safe dir to exist on the filesystem\n\n\nFix section (paste into the Fix / Patches field)\n\nFixed in [v1.25.0](https://github.com/fission/fission/releases/tag/v1.25.0) by:\n\n- [PR #3445](https://github.com/fission/fission/pull/3445) (commit [`8298e33e`](https://github.com/fission/fission/commit/8298e33ea7457702f893eae11077987cf905edb4)) — migrate every `SanitizeFilePath` call site (fetcher: `storePath` /\n`tmpPath` / `secretDir` / `configDir` / rename + `writeSecretOrConfigMap`; builder: `srcPkg` / `deployPkg` path validation and `srcPkg` stat) to new `pkg/utils/root.go` helpers (`RootJoin`, `RootStat`, `RootWriteFile`, `RootMkdirAll`,\n`RootRename`) that operate through `os.Root`. `os.Root` enforces directory confinement in the kernel and is recognized by CodeQL `go/path-injection` as a traversal barrier.\n- [PR #3446](https://github.com/fission/fission/pull/3446) (commit [`5aac6f0b`](https://github.com/fission/fission/commit/5aac6f0bcdf840e28f3f06c846ca7ae1866b3957)) — delete the deprecated `SanitizeFilePath` itself once no callers\nremained. The vulnerable function no longer exists in the tree.","aliases":["CVE-2026-50568","GO-2026-6130"],"modified":"2026-08-18T15:11:05.322729445Z","published":"2026-07-28T20:18:30Z","database_specific":{"github_reviewed_at":"2026-07-28T20:18:30Z","nvd_published_at":"2026-06-10T18:17:13Z","cwe_ids":["CWE-41"],"severity":"LOW","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/fission/fission/security/advisories/GHSA-r5jh-q2mw-gcx4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50568"},{"type":"WEB","url":"https://github.com/fission/fission/pull/3445"},{"type":"WEB","url":"https://github.com/fission/fission/pull/3446"},{"type":"WEB","url":"https://github.com/fission/fission/commit/5aac6f0bcdf840e28f3f06c846ca7ae1866b3957"},{"type":"WEB","url":"https://github.com/fission/fission/commit/8298e33ea7457702f893eae11077987cf905edb4"},{"type":"PACKAGE","url":"https://github.com/fission/fission"},{"type":"WEB","url":"https://github.com/fission/fission/releases/tag/v1.25.0"}],"affected":[{"package":{"name":"github.com/fission/fission","ecosystem":"Go","purl":"pkg:golang/github.com/fission/fission"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.25.0"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 1.24.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-r5jh-q2mw-gcx4/GHSA-r5jh-q2mw-gcx4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"}]}