<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T09:13:02.844894+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-32727</id>
    <title>CVE-2026-32727 — SciTokens: Authorization Bypass via Path Traversal in Scope Validation</title>
    <updated>2026-10-09T09:13:02.846631+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> scitokens</p>
<p>SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.7, the Enforcer is vulnerable to a path traversal attack where an attacker can use dot-dot (..) in the scope claim of a token to escape the intended directory restriction. This occurs because the library normalizes both the authorized path (from the token) and the requested path (from the application) before comparing them using startswith. This issue has been patched in version 1.9.7.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-32727"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3x2w-63fp-3qvw</id>
    <title>GHSA-3x2w-63fp-3qvw — SciTokens has an Authorization Bypass via Path Traversal in Scope Validation</title>
    <updated>2026-10-09T09:13:02.846687+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: scitokens</p>
<p>### Summary
The `Enforcer` is vulnerable to a path traversal attack where an attacker can use dot-dot (`..`) in the `scope` claim of a token to escape the intended directory restriction. This occurs because the library normalizes both the authorized path (from the token) and the requested path (from the application) before comparing them using `startswith`.</p>
<p>### Details
**File:** `src/scitokens/scitokens.py`  
**Methods:** `_check_scope`, `_scope_path_matches`  
**File:** `src/scitokens/urltools.py`  
**Method:** `normalize_path`</p>
<p>## Description
When a token is verified, the `Enforcer` extracts the authorized path from the `scope` or `scp` claim. This path is passed through `urltools.normalize_path`, which uses `posixpath.normpath` to resolve relative segments.</p>
<p>If a token has a scope like `read:/home/user1/..`, the normalization process converts this to `/home`. When the enforcer checks if a request for `/home/user2` is authorized, it compares it against the normalized path `/home`.</p>
<p>### Vulnerable Logic Flow:</p>
<p>1.  **Normalization:** In `_check_scope`, the path `/home/user1/..` is normalized to `/home`.
2.  **Comparison:** In `_scope_path_matches`, the requested path `/home/user2` is checked against the allowed path `/home`:
    ```python
    return requested_path.startswith(allowed_path + '/')
    # "/home/user2".startswith("/home/") is True
    ```</p>
<p>### Bypassing with URL Encoding:
Since `normalize_path` unquotes the path before normalizing, an attacker can also use URL-e…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3x2w-63fp-3qvw"/>
  </entry>
</feed>
