GHSA-r5jh-q2mw-gcx4
Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape
Quick fix
GHSA-r5jh-q2mw-gcx4 — github.com/fission/fission: upgrade to the fixed version with the command below.
go get github.com/fission/fission@v1.25.0 Details
`SanitizeFilePath` in `pkg/utils/utils.go` validated that a path stayed under a safe directory by calling `strings.HasPrefix(path, safedir)`. This is a lexical check, not a directory boundary check: `/packages-extra/evil` starts with `/packages`, so it passed. The function did not enforce a path-separator boundary, so any sibling directory whose name began with the safe-directory string was accepted.
Callers included the builder's `Clean` handler (`pkg/builder/builder.go:208`) and the fetcher's `Fetch` / `Upload` handlers (`pkg/fetcher/fetcher.go`). A tenant who could pre-create or control a sibling directory under the fetcher / builder's shared volume could induce a write or read outside the intended safe directory.
### Affected
- Project: `github.com/fission/fission` - Versions: all versions through v1.24.0 with `SanitizeFilePath` in the tree - Audited commit: `647c141` - Component: `pkg/utils/utils.go:SanitizeFilePath` - Callers: `pkg/builder/builder.go:157,164,208`, `pkg/fetcher/fetcher.go:296,311,450,496,565,571` - Configuration: default; requires a sibling directory to the safe dir to exist on the filesystem
Fix section (paste into the Fix / Patches field)
Fixed in [v1.25.0](https://github.com/fission/fission/releases/tag/v1.25.0) by:
- [PR #3445](https://github.com/fission/fission/pull/3445) (commit [`8298e33e`](https://github.com/fission/fission/commit/8298e33ea7457702f893eae11077987cf905edb4)) — migrate every `SanitizeFilePath` call site (fetcher: `storePath` / `tmpPath` / `secretDir` / `configDir` / rename + `writeSecretOrConfigMap`; builder: `srcPkg` / `deployPkg` path validation and `srcPkg` stat) to new `pkg/utils/root.go` helpers (`RootJoin`, `RootStat`, `RootWriteFile`, `RootMkdirAll`, `RootRename`) that operate through `os.Root`. `os.Root` enforces directory confinement in the kernel and is recognized by CodeQL `go/path-injection` as a traversal barrier. - [PR #3446](https://github.com/fission/fission/pull/3446) (commit [`5aac6f0b`](https://github.com/fission/fission/commit/5aac6f0bcdf840e28f3f06c846ca7ae1866b3957)) — delete the deprecated `SanitizeFilePath` itself once no callers remained. The vulnerable function no longer exists in the tree.
Are you affected?
Enter the version of the package you're using.
Affected packages
0 Fixed in: 1.25.0 go get github.com/fission/fission@v1.25.0 References
- https://github.com/fission/fission/security/advisories/GHSA-r5jh-q2mw-gcx4 [WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-50568 [ADVISORY]
- https://github.com/fission/fission/pull/3445 [WEB]
- https://github.com/fission/fission/pull/3446 [WEB]
- https://github.com/fission/fission/commit/5aac6f0bcdf840e28f3f06c846ca7ae1866b3957 [WEB]
- https://github.com/fission/fission/commit/8298e33ea7457702f893eae11077987cf905edb4 [WEB]
- https://github.com/fission/fission [PACKAGE]
- https://github.com/fission/fission/releases/tag/v1.25.0 [WEB]