Executive brief
BOSH Director, a tool used for deploying and managing cloud software, contains a vulnerability that could allow an attacker to read or delete sensitive files on the management server. By manipulating responses from a managed virtual machine, an attacker can trick the system into accessing files outside of its intended storage area. This could lead to the theft of configuration secrets or cause the management system to become inoperable.
Technical details
A path traversal vulnerability exists in BOSH Director's AgentClient when configured with a local blobstore provider. The 'inject_compile_log' and 'format_exception' functions consume agent-supplied JSON strings (compile_log_id or blobstore_id) and pass them unmodified to 'download_and_delete_blob'. Because 'Blobstore::LocalClient#object_file_path' uses 'File.join' without path normalization, an attacker who can control a BOSH agent's responses (e.g., via root access on a managed VM or NATS message injection) can provide a relative path like '../../' to escape the blobstore root. This allows the attacker to exfiltrate files by including them in task logs and subsequently delete them from the Director's filesystem.
Affected products
- Cloud Foundry Foundation BOSH Director All versions prior to v282.1.12
Timeline
- 2026-05-26: advisory: Cloud Foundry Foundation published the security advisory.
- 2026-05-27: disclosed: CVE-2026-41009 published to the NVD.