Directory Traversal Affecting scitokens-cpp package, versions <1.4.1-1


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.83% (53rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIANUNSTABLE-SCITOKENSCPP-15930626
  • published8 Apr 2026
  • disclosed31 Mar 2026

Introduced: 31 Mar 2026

CVE-2026-32725  (opens in a new tab)
CWE-23  (opens in a new tab)

How to fix?

Upgrade Debian:unstable scitokens-cpp to version 1.4.1-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream scitokens-cpp package and not the scitokens-cpp package as distributed by Debian. See How to fix? for Debian:unstable relevant fixed versions and status.

SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass when processing path-based scopes in tokens. The library normalizes the scope path from the token before authorization and collapses ".." path components instead of rejecting them. As a result, an attacker can use parent-directory traversal in the scope claim to broaden the effective authorization beyond the intended directory. This issue has been patched in version 1.4.1.