Description
SingularityCE and SingularityPRO are open source container platforms. Prior to SingularityCE 4.4.2 and SingularityPRO 4.3.9 and 4.1.14, incorrect path-string matching in the singularity.conf limit container paths directive allows a container in a sibling directory such as /data/safe-but-unsafe to be run when /data/safe is allowed under setuid mode. This permits a user to run a container from outside the administrator's configured path allowlist. Installations that do not use limit container paths are not affected. This issue is fixed in SingularityCE 4.4.2 and SingularityPRO 4.3.9 and 4.1.14.
Published: 2026-09-15
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized container execution with elevated privileges
Action: Patch immediately
AI Analysis

Impact

The flaw originates from a bug in the Singularity configuration processor that validates the 'limit container paths' directive. The validator incorrectly treats sibling directories as matches when evaluating the whitelist; for example, if /data/safe is permitted, a path such as /data/safe-but-unsafe is considered acceptable. A local user can run a container image located in that sibling directory while the binary executes in setuid mode, thereby gaining the setuid privileges. This bypasses the administrator‑configured allowlist and lets a non‑privileged user launch containers with elevated privileges, effectively turning the path restriction into a no‑op. The weakness is a path traversal style vulnerability, classified as CWE‑22.

Affected Systems

Vulnerable versions are SingularityCE prior to 4.4.2 and SingularityPRO prior to 4.3.9 (and 4.1.14). Installations that do not enable the limit container paths feature are unaffected. The issue affects systems that use the Sylabs Singularity platforms, including SingularityPRO and the open‑source SingularityCE.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate severity. The EPSS score of < 1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a local user that can launch containers in setuid mode; the attacker must have the ability to supply a container image and construct a path that falls outside the allowed list. Once the container runs, it inherits the privileges of the setuid executables, giving the attacker unauthorized system access. Because the exploit surface is limited to configurations that enable the limit container paths directive, careful review of the directive’s usage can mitigate risk.

Generated by OpenCVE AI on September 20, 2026 at 16:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to SingularityCE 4.4.2 or newer, or SingularityPRO 4.3.9 or 4.1.14, which contain the fix.
  • Ensure that setuid mode is only used when necessary, and that limit container paths is enabled with a strict whitelist of trusted directories.
  • If an upgrade cannot be performed immediately, configure singularity.conf to disable setuid mode or remove all containers that might be run under setuid mode until the patch is applied.

Generated by OpenCVE AI on September 20, 2026 at 16:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-wqcr-7rf3-f64m Singluarity: Incorrect path matching for 'limit container paths' directive
History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Sylabs
Sylabs singularity
Sylabs singularitypro
Vendors & Products Sylabs
Sylabs singularity
Sylabs singularitypro

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description SingularityCE and SingularityPRO are open source container platforms. Prior to SingularityCE 4.4.2 and SingularityPRO 4.3.9 and 4.1.14, incorrect path-string matching in the singularity.conf limit container paths directive allows a container in a sibling directory such as /data/safe-but-unsafe to be run when /data/safe is allowed under setuid mode. This permits a user to run a container from outside the administrator's configured path allowlist. Installations that do not use limit container paths are not affected. This issue is fixed in SingularityCE 4.4.2 and SingularityPRO 4.3.9 and 4.1.14.
Title Singularity: Incorrect path matching for 'limit container paths' directive
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L'}


Subscriptions

Sylabs Singularity Singularitypro
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T18:02:51.510Z

Reserved: 2026-05-18T22:25:21.258Z

Link: CVE-2026-47215

cve-icon Vulnrichment

Updated: 2026-09-15T17:38:22.715Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T16:17:11.170

Modified: 2026-09-25T14:23:59.847

Link: CVE-2026-47215

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T17:00:13Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')