๐Ÿ” CVE Alert

CVE-2026-32727

HIGH 8.1

SciTokens: Authorization Bypass via Path Traversal in Scope Validation

CVSS Score
8.1
EPSS Score
0.1%
EPSS Percentile
17th

SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.7, the Enforcer is vulnerable to a path traversal attack where an attacker can use dot-dot (..) in the scope claim of a token to escape the intended directory restriction. This occurs because the library normalizes both the authorized path (from the token) and the requested path (from the application) before comparing them using startswith. This issue has been patched in version 1.9.7.

CWE CWE-22
Vendor scitokens
Product scitokens
Published Mar 31, 2026
Last Updated Apr 2, 2026
Stay Ahead of the Next One

Get instant alerts for scitokens scitokens

Be the first to know when new high vulnerabilities affecting scitokens scitokens are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

scitokens / scitokens
< 1.9.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/scitokens/scitokens/security/advisories/GHSA-3x2w-63fp-3qvw github.com: https://github.com/scitokens/scitokens/pull/230 github.com: https://github.com/scitokens/scitokens/commit/2d1cc9e42bc944fe0bbc429b85d166e7156d53f9 github.com: https://github.com/scitokens/scitokens/releases/tag/v1.9.7