GHSA-2r75-cxrj-cmph

Suggest an improvement
Source
https://github.com/advisories/GHSA-2r75-cxrj-cmph
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-2r75-cxrj-cmph/GHSA-2r75-cxrj-cmph.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-2r75-cxrj-cmph
Aliases
Downstream
Published
2026-06-05T15:47:02Z
Modified
2026-09-10T03:51:07Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
wasmtime-wasi: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction
Details

Summary

In wasmtime-wasi, when a filesystem preopen is given DirPerms::all() and FilePerms::READ without FilePerms::WRITE, this wasmtime-wasi enforced access control mechanism can be bypassed by using the wasip2 descriptor.open-at or wasip1 path_open interfaces by opening a file with OpenFlags::TRUNCATE oflag only, for example:

dir_descriptor.open_at(
   PathFlags::empty(),
   FILENAME,
   OpenFlags::TRUNCATE,
   DescriptorFlags::READ,
)
wasip1::path_open(
    dir_fd,
    0,
    FILENAME,
    wasip1::OFLAGS_TRUNC,
    wasip1::RIGHTS_FD_READ,
    0,
    0
)

The root cause is that the clause that considered OpenFlags::TRUNCATE did not set open_mode |= OpenMode::WRITE;, used later in that function for the access control check against FilePerms for whether opening that file is permitted. With the bug corrected, these calls to open-at and path_open fail with error-code.not-permitted and ERRNO_PERM respectively.

The bug in crates/wasi/src/filesystem.rs, Dir::open_at, lines 967–969:

if oflags.contains(OpenFlags::TRUNCATE) {
    opts.truncate(true).write(true);
}

and the single line fix is:

if oflags.contains(OpenFlags::TRUNCATE) {
    opts.truncate(true).write(true);
    open_mode |= OpenMode::WRITE;
}

Only wasmtime-wasi embeddings that use a combination of DirPerms::MUTATE with FilePerms::READ are affected by this bug, e.g. those that use in the WasiCtxBuilder:

builder.preopened_dir("readonly", "readonly", DirPerms::READ | DirPerms::MUTATE, FilePerms::READ);

In particular, the Wasmtime project's wasmtime-cli's use of wasmtime-wasi is not affected, because it always sets FilePerms::all() for all preopens.

Database specific
{
    "cwe_ids": [
        "CWE-284"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-06-05T15:47:02Z",
    "nvd_published_at": "2026-06-15T21:17:11Z",
    "severity": "HIGH"
}
References

Affected packages

crates.io / wasmtime-wasi

Package

Name
wasmtime-wasi
View open source insights on deps.dev
Purl
pkg:cargo/wasmtime-wasi

Affected ranges

Type
SEMVER
Events
Introduced
37.0.0
Fixed
44.0.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-2r75-cxrj-cmph/GHSA-2r75-cxrj-cmph.json"

crates.io / wasmtime-wasi

Package

Name
wasmtime-wasi
View open source insights on deps.dev
Purl
pkg:cargo/wasmtime-wasi

Affected ranges

Type
SEMVER
Events
Introduced
25.0.0
Fixed
36.0.10

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-2r75-cxrj-cmph/GHSA-2r75-cxrj-cmph.json"

crates.io / wasmtime-wasi

Package

Name
wasmtime-wasi
View open source insights on deps.dev
Purl
pkg:cargo/wasmtime-wasi

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
24.0.9

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-2r75-cxrj-cmph/GHSA-2r75-cxrj-cmph.json"