VDB
Sign up
HIGH8.1

GHSA-gv5w-hfx8-8cwq

SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths

Quick fix

GHSA-gv5w-hfx8-8cwq — github.com/seaweedfs/seaweedfs: upgrade to the fixed version with the command below.

go get github.com/seaweedfs/seaweedfs@v0.0.0-20260512171048-05ed5c9ae8a2

Details

### Impact When a filer JWT restricts a token to a set of path prefixes via `allowed_prefixes`, the authorization check used a literal byte-prefix match (`strings.HasPrefix`). A token scoped to `/tenant1` therefore also authorized requests to sibling paths such as `/tenant1234`, `/tenant1-old`, and `/tenant1backup`.

In a multi-tenant deployment this lets the holder of one tenant's token access another tenant's data. Because `allowed_prefixes` gates both read and write tokens, the impact covers cross-tenant reads and writes. A valid scoped token is required, so this is an authorization bypass rather than a fully unauthenticated flaw.

### Affected component - `weed/server/filer_server_handlers.go` (JWT `allowed_prefixes` authorization check)

### Patches Fixed in **4.24**. The check now matches on `/`-separated path components after `path.Clean` normalisation, so `/tenant1` authorizes only `/tenant1` and its descendants — not `/tenant1234` or other sibling paths.

### Workarounds Where feasible, choose prefix names that are not string-prefixes of one another (e.g. keep a trailing separator convention). Upgrade to 4.24.

### References - Reported by Kadir Arslan (https://github.com/KadirArslan)

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/seaweedfs/seaweedfs
Introduced in: 0Fixed in: 0.0.0-20260512171048-05ed5c9ae8a2
Fixgo get github.com/seaweedfs/seaweedfs@v0.0.0-20260512171048-05ed5c9ae8a2

References