Description
Nextflow is a DSL for data-driven computational pipelines. From 25.09.2-edge until 25.10.6 and 26.04.3, nextflow auth login writes Seqera Platform OIDC bearer tokens to ${NXF_HOME:-~/.nextflow}/seqera-auth.config through AuthCommandImpl.writeConfig in plugins/nf-tower/src/main/io/seqera/tower/plugin/auth/AuthCommandImpl.groovy without setting restrictive file permissions, allowing the default umask 022 to create the file with mode 0644. On a multi-user POSIX host, a local user who can traverse the victim's home directory can read seqera-auth.config and impersonate the victim against Seqera Platform within the token's scope. Single-user systems and headless CI runners that do not use the interactive login flow are not affected. This issue is fixed in 25.10.6 and 26.04.3.
Published: 2026-09-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access through token theft
Action: Patch
AI Analysis

Impact

Nextflow erroneously writes Seqera Platform OIDC bearer tokens to a configuration file with default permissions set to 0644. This allows a local user home directory to read the token and impersonate the victim against the Seqera Platform within the token’s privileges, potentially exposing confidential data or executing actions as if they were the victim.

Affected Systems

The vulnerability exists in Nextflow versions from 25.09.2-edge through 25.10.6 and in 26.04.3. All affected installations write the token to ${NXF_HOME:-~/.nextflow}/seqera-auth.config without restrictive permissions.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity, while the EPSS score is < 1%. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access on a multi‑user POSIX host; a user who can read the victim’s home directory can retrieve the bearer token and use it to authenticate to the Seqera Platform, effectively performing unauthorized actions. The issue is already fixed in newer releases of Nextflow.

Generated by OpenCVE AI on September 17, 2026 at 15:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Nextflow 25.10.6 or later (including 26.04.3) where the file permissions are correctly set.
  • If an upgrade is not immediately possible, manually change the permissions of ${NXF_HOME}/seqera-auth.config to 0600 or use a restrictive umask such as 077 when running the auth login command.
  • Ensure that the victim’s home directory is protected from traversal by other local users, especially on multi‑user systems.

Generated by OpenCVE AI on September 17, 2026 at 15:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-92qf-fcph-v5wr nextflow auth login command has incorrect default permissions
History

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Nextflow is a DSL for data-driven computational pipelines. From 25.09.2-edge until 25.10.6 and 26.04.3, nextflow auth login writes Seqera Platform OIDC bearer tokens to ${NXF_HOME:-~/.nextflow}/seqera-auth.config through AuthCommandImpl.writeConfig in plugins/nf-tower/src/main/io/seqera/tower/plugin/auth/AuthCommandImpl.groovy without setting restrictive file permissions, allowing the default umask 022 to create the file with mode 0644. On a multi-user POSIX host, a local user who can traverse the victim's home directory can read seqera-auth.config and impersonate the victim against Seqera Platform within the token's scope. Single-user systems and headless CI runners that do not use the interactive login flow are not affected. This issue is fixed in 25.10.6 and 26.04.3.
Title Nextflow: Incorrect default permissions in the nextflow auth login command
Weaknesses CWE-276
CWE-732
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T14:28:18.251Z

Reserved: 2026-05-22T18:47:27.756Z

Link: CVE-2026-48722

cve-icon Vulnrichment

Updated: 2026-09-17T14:28:12.450Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T15:17:16.020

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-48722

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T15:45:17Z

Weaknesses
  • CWE-276

    Incorrect Default Permissions

  • CWE-732

    Incorrect Permission Assignment for Critical Resource