Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape
🔗 CVE IDs covered (1)
📋 Description
SanitizeFilePath in pkg/utils/utils.go validated that a path stayed under a safe directory by calling strings.HasPrefix(path, safedir). This is a lexical check, not a directory boundary check: /packages-extra/evil starts with
/packages, so it passed. The function did not enforce a path-separator boundary, so any sibling directory whose name began with the safe-directory string was accepted.
Callers included the builder's Clean handler (pkg/builder/builder.go:208) and the fetcher's Fetch / Upload handlers (pkg/fetcher/fetcher.go). A tenant who could pre-create or control a sibling directory under the fetcher /
builder's shared volume could induce a write or read outside the intended safe directory.
Affected
- Project:
github.com/fission/fission - Versions: all versions through v1.24.0 with
SanitizeFilePathin the tree - Audited commit:
647c141 - Component:
pkg/utils/utils.go:SanitizeFilePath - Callers:
pkg/builder/builder.go:157,164,208,pkg/fetcher/fetcher.go:296,311,450,496,565,571 - Configuration: default; requires a sibling directory to the safe dir to exist on the filesystem
Fix section (paste into the Fix / Patches field)
Fixed in v1.25.0 by:
- PR #3445 (commit
8298e33e) — migrate everySanitizeFilePathcall site (fetcher:storePath/tmpPath/secretDir/configDir/ rename +writeSecretOrConfigMap; builder:srcPkg/deployPkgpath validation andsrcPkgstat) to newpkg/utils/root.gohelpers (RootJoin,RootStat,RootWriteFile,RootMkdirAll,RootRename) that operate throughos.Root.os.Rootenforces directory confinement in the kernel and is recognized by CodeQLgo/path-injectionas a traversal barrier. - PR #3446 (commit
5aac6f0b) — delete the deprecatedSanitizeFilePathitself once no callers remained. The vulnerable function no longer exists in the tree.
🎯 Affected products1
- go/github.com/fission/fission:<= 1.24.0
🔗 References (8)
- https://github.com/fission/fission/security/advisories/GHSA-r5jh-q2mw-gcx4
- https://nvd.nist.gov/vuln/detail/CVE-2026-50568
- https://github.com/fission/fission/pull/3445
- https://github.com/fission/fission/pull/3446
- https://github.com/fission/fission/commit/5aac6f0bcdf840e28f3f06c846ca7ae1866b3957
- https://github.com/fission/fission/commit/8298e33ea7457702f893eae11077987cf905edb4
- https://github.com/fission/fission/releases/tag/v1.25.0
- https://github.com/advisories/GHSA-r5jh-q2mw-gcx4