PT-2026-48933 · Apptainer · Apptainer

CVE-2026-48785

·

Published

2026-06-10

·

Updated

2026-07-30

CVSS v3.1

4.8

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions apptainer versions prior to 1.5.1
Description Incorrect path matching occurs within the limit container paths directive. This issue specifically affects SUID installations where paths listed in limit container paths are string prefixes of other existing paths that should not be included. For example, if /scratch is listed as a permitted path but /scratch2 also exists and contains container images, the system would previously match and include /scratch2 incorrectly. The fix ensures that only images under the exactly matching path are included.
Recommendations Update apptainer to version 1.5.1.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48785
GHSA-CR2J-534F-MF3G
GO-2026-5805
OPENSUSE-SU-2026:10993-1
OPENSUSE-SU-2026:20942-1
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:2609-1

Affected Products

Apptainer