VDB
Sign up
HIGH8.4

GHSA-4mq4-7rw3-vm5j

Wasmer filesystem sandbox not enforced

Details

### Summary As of Wasmer version v4.2.3, Wasm programs can access the filesystem outside of the sandbox.

### Details https://github.com/wasmerio/wasmer/issues/4267

### PoC A minimal Rust program:

``` fn main() { let f = std::fs::OpenOptions::new() .write(true) .create_new(true) .open("abc") .unwrap(); } ```

This should be compiled with `cargo build --target wasm32-wasi`. The compiled program, when run with wasmer WITHOUT `--dir`, can still create a file in the working directory.

### Impact Service providers running untrusted Wasm code on Wasmer can unexpectedly expose the host filesystem.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/wasmer-cli
Introduced in: 3.0.0Fixed in: 4.2.4

Upgrade wasmer-cli to 4.2.4 or newer (ecosystem crates.io).

References