Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-wqcr-7rf3-f64m | Singluarity: Incorrect path matching for 'limit container paths' directive |
Tue, 15 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sylabs
Sylabs singularity Sylabs singularitypro |
|
| Vendors & Products |
Sylabs
Sylabs singularity Sylabs singularitypro |
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SingularityCE and SingularityPRO are open source container platforms. Prior to SingularityCE 4.4.2 and SingularityPRO 4.3.9 and 4.1.14, incorrect path-string matching in the singularity.conf limit container paths directive allows a container in a sibling directory such as /data/safe-but-unsafe to be run when /data/safe is allowed under setuid mode. This permits a user to run a container from outside the administrator's configured path allowlist. Installations that do not use limit container paths are not affected. This issue is fixed in SingularityCE 4.4.2 and SingularityPRO 4.3.9 and 4.1.14. | |
| Title | Singularity: Incorrect path matching for 'limit container paths' directive | |
| Weaknesses | CWE-22 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-15T18:02:51.510Z
Reserved: 2026-05-18T22:25:21.258Z
Link: CVE-2026-47215
Updated: 2026-09-15T17:38:22.715Z
Status : Received
Published: 2026-09-15T16:17:11.170
Modified: 2026-09-15T19:17:19.847
Link: CVE-2026-47215
No data.
OpenCVE Enrichment
Updated: 2026-09-15T16:45:06Z
Github GHSA