Description
Apptainer is an open source container platform. Prior to version 1.5.1, Image.AuthorizedPath applies plain string-prefix matching to the limit container paths directive in apptainer.conf, so an allowed path such as /data/safe also authorizes a sibling path such as /data/safe-but-unsafe. A local user can consequently run a container from a directory outside the administrator's intended allowlist when Apptainer operates in setuid mode. Installations that do not use setuid mode or do not configure limit container paths are not affected, and unrestricted user namespaces already allow users to run containers of their choice. This issue is fixed in version 1.5.1.
Published: 2026-09-15
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized privilege escalation within containers via setuid mode
Action: Patch
AI Analysis

Impact

Apptainer is an open‑source container platform that restricts which directories a container image may be built from via the limit container paths directive in apptainer.conf. In releases before 1.5.1 the directive performs a plain string‑prefix match, so an allowed path such as "/data/safe" also authorizes a sibling path like "/data/safe-but-unsafe". When Apptainer runs with its setuid binary, a local user can therefore launch a container from an unintended directory that lies outside the administrator’s intended allowlist. Installations that do not use setuid mode or that do not configure the limit container paths directive are not affected, and user namespaces already permit users to run containers of their choice.

Affected Systems

Apptainer versions before 1.5.1 are affected when the setuid binary is used and the limit container paths directive is enabled. Installations that do not use the setuid binary or that do not specify the limit container paths directive are not vulnerable. Unprivileged containers that run through user namespaces also remain unaffected because they do not rely on this directive.

Risk and Exploitability

The CVSS score of 4.8 places this vulnerability in the medium severity range. The EPSS score is reported as < 1% and the issue is not listed in the CISA KEV catalog. The attack vector is local: an attacker who can execute commands on the host and invoke the setuid Apptainer binary can exploit the flaw to run a container from an unintended directory while still exercising the elevated privileges granted to the setuid binary. The fix is to upgrade to version 1.5.1 or later, which implements exact path matching for the limit container paths directive.

Generated by OpenCVE AI on September 20, 2026 at 14:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apptainer to version 1.5.1 or later, which implements exact path matching for the limit container paths directive.
  • Disable setuid mode if it is not required for your workflow and rely on user namespaces for containment.
  • Review the directories listed in the limit container paths directive to ensure no unintended sibling paths can be matched.

Generated by OpenCVE AI on September 20, 2026 at 14:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-cr2j-534f-mf3g Apptainer has incorrect path matching for 'limit container paths' directive
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Apptainer
Apptainer apptainer
Vendors & Products Apptainer
Apptainer apptainer

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Apptainer is an open source container platform. Prior to version 1.5.1, Image.AuthorizedPath applies plain string-prefix matching to the limit container paths directive in apptainer.conf, so an allowed path such as /data/safe also authorizes a sibling path such as /data/safe-but-unsafe. A local user can consequently run a container from a directory outside the administrator's intended allowlist when Apptainer operates in setuid mode. Installations that do not use setuid mode or do not configure limit container paths are not affected, and unrestricted user namespaces already allow users to run containers of their choice. This issue is fixed in version 1.5.1.
Title Apptainer: Incorrect path matching for 'limit container paths' directive
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L'}


Subscriptions

Apptainer Apptainer
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T17:38:10.029Z

Reserved: 2026-05-22T20:18:20.365Z

Link: CVE-2026-48785

cve-icon Vulnrichment

Updated: 2026-09-15T17:38:06.771Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T18:17:21.640

Modified: 2026-09-25T14:10:13.927

Link: CVE-2026-48785

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:00:11Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')