Singularity: Incorrect path matching for 'limit container paths' directive
Summary
| CVE | CVE-2026-47215 |
|---|---|
| State | PUBLISHED |
| Assigner | GitHub_M |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-15 16:17:11 UTC |
| Updated | 2026-09-25 14:23:59 UTC |
| Description | SingularityCE and SingularityPRO are open source container platforms. Prior to SingularityCE 4.4.2 and SingularityPRO 4.3.9 and 4.1.14, incorrect path-string matching in the singularity.conf limit container paths directive allows a container in a sibling directory such as /data/safe-but-unsafe to be run when /data/safe is allowed under setuid mode. This permits a user to run a container from outside the administrator's configured path allowlist. Installations that do not use limit container paths are not affected. This issue is fixed in SingularityCE 4.4.2 and SingularityPRO 4.3.9 and 4.1.14. |
Risk And Classification
Primary CVSS: v3.1 4.8 MEDIUM from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
EPSS: 0.001550000 probability, percentile 0.039260000 (date 2026-09-27)
Problem Types: CWE-22 | CWE-22 CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 4.8 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L |
| 3.1 | CNA | DECLARED | 4.8 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
RequiredScope
UnchangedConfidentiality
LowIntegrity
LowAvailability
LowCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Sylabs | Singularity | affected < 4.4.2 | Not specified |
| CNA | Sylabs | SingularityPRO | affected < 4.1.14 | Not specified |
| CNA | Sylabs | SingularityPRO | affected >= 4.2.0, < 4.3.9 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/sylabs/singularity/pull/4152 | [email protected] | github.com | |
| github.com/sylabs/singularity/releases/tag/v4.4.2 | [email protected] | github.com | |
| github.com/sylabs/singularity/security/advisories/GHSA-wqcr-7rf3-f64m | [email protected] | github.com | |
| github.com/sylabs/singularity/commit/c08791793e843d4c9c1f2fc1d9d12abef74... | [email protected] | github.com | |
| github.com/sylabs/singularity/commit/c1dc9470a769e6e534b588a4ed521768ca4... | [email protected] | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.