SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access
41Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 7.8epss 0.4%
de la publicación al arma41 días
Publicada en NVD25 jun
1ª PoC+41d
probabilidad de explotación
0.4%top 69% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
SeaweedFS is a distributed storage system for object storage (S3), file systems, and Iceberg tables. Prior to 4.30, the S3 API gateway and the Iceberg REST catalog gateway construct their routers with mux.NewRouter().SkipClean(true). With path cleaning disabled, a .. segment inside the URL survives routing, so a request such as `GET /bucket-A/../evil-bucket/key`, is matched as bucket=bucket-A, object=../evil-bucket/key. The captured object key is then joined into a filer path with util.JoinPath (S3) / path.Join (Iceberg), which collapse the .. server-side, so the actual read or write lands in evil-bucket. This vulnerability is fixed in 4.30.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N
Productos afectados
seaweedfs · seaweedfsPoCs públicas encontradas — 1
githubgithub.com/BiiTts/CVE-2026-54917-SeaweedFS-Cross-Bucket-Traversal★ 0⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.