Impact
Nextflow erroneously writes Seqera Platform OIDC bearer tokens to a configuration file with default permissions set to 0644. This allows a local user home directory to read the token and impersonate the victim against the Seqera Platform within the token’s privileges, potentially exposing confidential data or executing actions as if they were the victim.
Affected Systems
The vulnerability exists in Nextflow versions from 25.09.2-edge through 25.10.6 and in 26.04.3. All affected installations write the token to ${NXF_HOME:-~/.nextflow}/seqera-auth.config without restrictive permissions.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while the EPSS score is < 1%. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access on a multi‑user POSIX host; a user who can read the victim’s home directory can retrieve the bearer token and use it to authenticate to the Seqera Platform, effectively performing unauthorized actions. The issue is already fixed in newer releases of Nextflow.
OpenCVE Enrichment
Github GHSA