Description
A flaw was found in operator-foundry. The path-containment check, designed to restrict file access within a build context, only performs string-based validation. It fails to resolve symbolic links (symlinks), allowing an attacker to create a symlink within the build context that points to files or directories outside of it. This could enable unauthorized access to files beyond the intended confinement.
Published: n/a
Score: 2.6 Low
EPSS: n/a
KEV: No
Impact: Unauthorized File Access
Action: Patch
AI Analysis

Impact

The flaw in operator‑foundry’s resolveAndValidatePath uses only lexical containment checks, ignoring symbolic links. An attacker can place a symlink inside the build context that points to a file or directory outside the intended boundary, thereby obtaining unauthorized access to sensitive resources beyond the confined environment.

Affected Systems

This vulnerability affects installations of operator‑foundry. The specific affected versions are not enumerated in the advisory, so all variants that employ the current resolveAndValidatePath logic are potentially susceptible.

Risk and Exploitability

The CVSS score of 2.6 indicates low impact, and the EPSS score is unavailable, so current exploitation probability is unclear. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploits. Nevertheless, the attack vector is local or could be triggered during a build process, allowing an adversary with write access to the build context to read arbitrary files outside the context by exploiting the symlink bypass.

Generated by OpenCVE AI on September 9, 2026 at 06:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and deploy the operator‑foundry update that includes a robust path normalization routine.
  • If a patch is not yet released, configure the build environment to deny symlink creation or to remove existing symlinks before path validation.
  • Implement a monitoring rule to alert when files outside the build context are accessed during the build process.

Generated by OpenCVE AI on September 9, 2026 at 06:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in operator-foundry. The path-containment check, designed to restrict file access within a build context, only performs string-based validation. It fails to resolve symbolic links (symlinks), allowing an attacker to create a symlink within the build context that points to files or directories outside of it. This could enable unauthorized access to files beyond the intended confinement.
Title operator-foundry: operator-foundry: resolveAndValidatePath performs lexical containment only — symlinks can escape the build context
Weaknesses CWE-59
References
Metrics threat_severity

None

cvssV3_1

{'score': 2.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N'}

threat_severity

Low


Subscriptions

No data.

cve-icon MITRE

No data.

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-08T19:00:00Z

Links: CVE-2026-87051 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T07:00:09Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')