PYSEC-2026-2277

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/scitokens/PYSEC-2026-2277.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2026-2277
Aliases
Published
2026-03-31T03:15:57.340Z
Modified
2026-07-13T07:15:42.375575025Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.7, the Enforcer is vulnerable to a path traversal attack where an attacker can use dot-dot (..) in the scope claim of a token to escape the intended directory restriction. This occurs because the library normalizes both the authorized path (from the token) and the requested path (from the application) before comparing them using startswith. This issue has been patched in version 1.9.7.

References

Affected packages

PyPI / scitokens

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.7

Affected versions

0.*
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
1.*
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/scitokens/PYSEC-2026-2277.yaml"