When running the AWS Serverless Application Model Command Line Interface (SAM CLI) build process with Docker and symlinks are included in the build files, the container environment allows a user to access privileged files on the host by leveraging the elevated permissions granted to the tool. A user could leverage the elevated permissions to access restricted files via symlinks and copy them to a more permissive location on the container.

Users should upgrade to v1.133.0 or newer and ensure any forked or derivative code is patched to incorporate the new fixes.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-8754 AWS SAM CLI Path Traversal allows file copy to build container
Github GHSA Github GHSA GHSA-px37-jpqx-97q9 AWS SAM CLI Path Traversal allows file copy to build container
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 14 Oct 2025 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
CWE-497

Tue, 14 Oct 2025 19:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-61

Tue, 14 Oct 2025 18:45:00 +0000

Type Values Removed Values Added
References

Mon, 31 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Mar 2025 17:00:00 +0000


Mon, 31 Mar 2025 15:30:00 +0000

Type Values Removed Values Added
Description When running the AWS Serverless Application Model Command Line Interface (SAM CLI) build process with Docker and symlinks are included in the build files, the container environment allows a user to access privileged files on the host by leveraging the elevated permissions granted to the tool. A user could leverage the elevated permissions to access restricted files via symlinks and copy them to a more permissive location on the container. Users should upgrade to v1.133.0 or newer and ensure any forked or derivative code is patched to incorporate the new fixes.
Title Path Traversal in AWS SAM CLI allows file copy to build container
Weaknesses CWE-22
CWE-497
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2025-10-14T19:22:56.059Z

Reserved: 2025-03-31T13:32:50.477Z

Link: CVE-2025-3047

cve-icon Vulnrichment

Updated: 2025-03-31T16:19:58.059Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-03-31T16:15:27.683

Modified: 2025-10-14T20:15:36.377

Link: CVE-2025-3047

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.