GHSA-fgmf-7rf8-m6vf
ZITADEL: Actions V1 sandbox escape: host file read via require()
Quick fix
GHSA-fgmf-7rf8-m6vf — github.com/zitadel/zitadel: upgrade to the fixed version with the command below.
go get github.com/zitadel/zitadel@v1.80.0-v2.20.0.20260717062331-baf6ed501b68Details
### Summary
A vulnerability in ZITADEL Actions V1 allows an organization Action author to read files from the ZITADEL host filesystem through the JavaScript `require()` module loader. On common self-hosted deployments this can be chained to steal bootstrap credentials (including the Login Client PAT) and escalate from a single-tenant organization owner to instance administrator.
### Impact
ZITADEL Actions V1 run custom JavaScript inside the ZITADEL server process at OIDC, SAML, and login-flow trigger points. The runtime enables the goja Node-compatible `require()` registry without restricting the source loader, so Action scripts can load host files readable by the ZITADEL process (notably `.js` and `.json`, and in some cases other file contents via error channels).
An attacker with **ORG_OWNER** on any organization (which includes `org.action.write` and `org.flow.write`) can therefore:
* Read process-readable host files, including configuration or secrets mounted into the API container (for example service-account material, projected secrets, or config carrying sensitive values). * On deployments that follow ZITADEL’s documented bootstrap paths (`ZITADEL_FIRSTINSTANCE_LOGINCLIENTPATPATH`, `ZITADEL_FIRSTINSTANCE_MACHINEKEYPATH`), recover instance-wide credentials such as the **IAM_LOGIN_CLIENT** PAT or the **IAM_OWNER** service-account key, enabling escalation to full instance control.
This collapses the expected multi-tenant isolation boundary: a tenant organization administrator is not meant to access host filesystem secrets or instance-wide credentials.
**Scope note:** This issue affects **Actions V1**. Host command execution was not identified as part of this vulnerability. Impact depends on what the ZITADEL process can read on disk and on deployment layout — documented Compose and quick-start setups that write bootstrap PATs or machine keys into the API container amplify severity.
### Affected Versions
Systems running one of the following versions are affected:
* **4.x:** `4.0.0` through `4.16.0` (including RC versions) * **3.x:** `3.0.0` through `3.4.12` (including RC versions)
### Patches
The vulnerability has been addressed in the latest releases. The patch disables filesystem-backed module loading for Action scripts so that only the intended native `zitadel/*` modules can be required.
* **4.x**: Upgrade to $\ge$ [4.16.1](https://github.com/zitadel/zitadel/releases/tag/v4.16.1) * **3.x**: Upgrade to $\ge$ [3.4.13](https://github.com/zitadel/zitadel/releases/tag/v3.4.13)
### Workarounds
If an immediate upgrade is not possible:
* Restrict who can create, update, or attach Actions — do not grant `org.action.write` / `org.flow.write` (or **ORG_OWNER**) to untrusted administrators in multi-tenant environments. * Audit existing Actions for `require()` of filesystem paths. * Remove or relocate bootstrap credential files (`login-client.pat`, machine keys) so they are not readable inside the API process filesystem. * Limit host filesystem exposure for the ZITADEL process (no unnecessary readable secrets beside the binary).
### Questions
If you have any questions or comments about this advisory, please email us at [security@zitadel.com](mailto:security@zitadel.com)
### Credits
Thanks to Dor Konis ([@dkonis](https://github.com/dkonis)) and Feras Daragma ([@FerasTr](https://github.com/FerasTr)) from GE Vernova, and to [pyuysig](https://github.com/pyuysig), for finding and reporting this vulnerability.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 1.80.0-v2.20.0.20260717062331-baf6ed501b68go get github.com/zitadel/zitadel@v1.80.0-v2.20.0.20260717062331-baf6ed501b68References
- https://github.com/zitadel/zitadel/security/advisories/GHSA-fgmf-7rf8-m6vf[WEB]
- https://github.com/zitadel/zitadel/commit/afe108640cf57a17e8b743fbcdad9ae636eb3eb7[WEB]
- https://github.com/zitadel/zitadel/commit/baf6ed501b684f47048553d9034e8d3aa824950e[WEB]
- https://github.com/zitadel/zitadel/commit/e28d6bcc033368c3e9683ee15c195b8460b9305d[WEB]
- https://github.com/zitadel/zitadel[PACKAGE]
- https://github.com/zitadel/zitadel/releases/tag/v3.4.13[WEB]
- https://github.com/zitadel/zitadel/releases/tag/v4.16.1[WEB]