{"schema_version":"1.7.5","id":"GHSA-cr2j-534f-mf3g","published":"2026-06-26T19:20:33Z","modified":"2026-07-07T16:11:14.797679488Z","aliases":["CVE-2026-48785","GO-2026-5805"],"summary":"Apptainer has incorrect path matching for 'limit container paths' directive ","details":"### Impact\n\nThe `limit container paths directive` in `apptainer.conf` is intended to allow a system administrator limit the paths from which containers can be run, under setuid mode. Due to incorrect matching of a path string, sibling directories with similar names may incorrectly be allowed.\n\nFor example, the configuration:\n```\nlimit container paths = /data/safe\n```\nWill also allow containers in /data/safe-but-unsafe to be run.\n\n### Patches\n\nThe issue is patched in apptainer version 1.5.1.\n\n### Workarounds\n\nIf developers do not use setuid mode or do not use the `limit container paths` functionality, then this issue does not affect their installation. Note that, as documented [1], if user namespaces are allowed for unrestricted use then this functionality does not stop users from running any container of their choice.\n\nIf developers do use the `limit container paths` functionality they are advised to update.\n\n### Credit\n\nThis vulnerability was discovered and disclosed to the Apptainer project by Dave Trudgian of Sylabs.\n\n### Resources\n\n[1] https://apptainer.org/docs/admin/latest/configfiles.html#limiting-container-execution","affected":[{"package":{"name":"github.com/apptainer/apptainer","ecosystem":"Go","purl":"pkg:golang/github.com/apptainer/apptainer"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.5.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-cr2j-534f-mf3g/GHSA-cr2j-534f-mf3g.json"}}],"references":[{"type":"WEB","url":"https://github.com/apptainer/apptainer/security/advisories/GHSA-cr2j-534f-mf3g"},{"type":"PACKAGE","url":"https://github.com/apptainer/apptainer"}],"database_specific":{"cwe_ids":["CWE-22"],"github_reviewed":true,"github_reviewed_at":"2026-06-26T19:20:33Z","nvd_published_at":null,"severity":"MODERATE"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L"}]}