๐Ÿ” CVE Alert

CVE-2026-50568

LOW 3.6

Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape

CVSS Score
3.6
EPSS Score
0.0%
EPSS Percentile
0th

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.25.0, SanitizeFilePath in pkg/utils/utils.go validated that a path stayed under a safe directory by calling strings.HasPrefix(path, safedir). This is a lexical check, not a directory boundary check: /packages-extra/evil starts with /packages, so it passed. The function did not enforce a path-separator boundary, so any sibling directory whose name began with the safe-directory string was accepted. Callers included the builder's Clean handler (pkg/builder/builder.go:208) and the fetcher's Fetch / Upload handlers (pkg/fetcher/fetcher.go). A tenant who could pre-create or control a sibling directory under the fetcher / builder's shared volume could induce a write or read outside the intended safe directory. This issue has been patched in version 1.25.0.

CWE CWE-41
Vendor fission
Product fission
Published Jun 10, 2026
Stay Ahead of the Next One

Get instant alerts for fission fission

Be the first to know when new low vulnerabilities affecting fission fission are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

fission / fission
< 1.25.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/fission/fission/security/advisories/GHSA-r5jh-q2mw-gcx4 github.com: https://github.com/fission/fission/pull/3445 github.com: https://github.com/fission/fission/pull/3446 github.com: https://github.com/fission/fission/releases/tag/v1.25.0