PT-2026-46880 · Unknown · Singularity+1
CVE-2026-47215
·
Published
2026-06-04
·
Updated
2026-07-30
CVSS v3.1
4.8
Medium
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
SingularityCE versions prior to 4.4.2
SingularityPRO versions prior to 4.3.9
SingularityPRO versions prior to 4.1.14
Description
Incorrect path string matching occurs within the
limit container paths directive in singularity.conf, which is designed to restrict the paths from which containers can be executed under setuid mode. This flaw allows sibling directories with similar names to be incorrectly permitted. For instance, a configuration intended to limit paths to /data/safe would also allow containers located in /data/safe-but-unsafe to run.Recommendations
Update SingularityCE to version 4.4.2.
Update SingularityPRO to version 4.3.9.
Update SingularityPRO to version 4.1.14.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Singularity
Singularitypro