CVE-2026-32727
SciTokens: Authorization Bypass via Path Traversal in Scope Validation
CVSS Score
8.1
EPSS Score
0.1%
EPSS Percentile
17th
SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.7, the Enforcer is vulnerable to a path traversal attack where an attacker can use dot-dot (..) in the scope claim of a token to escape the intended directory restriction. This occurs because the library normalizes both the authorized path (from the token) and the requested path (from the application) before comparing them using startswith. This issue has been patched in version 1.9.7.
| CWE | CWE-22 |
| Vendor | scitokens |
| Product | scitokens |
| Published | Mar 31, 2026 |
| Last Updated | Apr 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for scitokens scitokens
Be the first to know when new high vulnerabilities affecting scitokens scitokens are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Affected Versions
scitokens / scitokens
< 1.9.7
References
github.com: https://github.com/scitokens/scitokens/security/advisories/GHSA-3x2w-63fp-3qvw github.com: https://github.com/scitokens/scitokens/pull/230 github.com: https://github.com/scitokens/scitokens/commit/2d1cc9e42bc944fe0bbc429b85d166e7156d53f9 github.com: https://github.com/scitokens/scitokens/releases/tag/v1.9.7