Junglewise Threat Intelligence

CVE-2026-47215: SingularityCE and SingularityPRO are open source container platforms. Prior to SingularityCE 4.4.2 and SingularityPRO 4.3.9 and 4.1.14, inco

CVE-2026-47215 · Severity: medium · CVSS 4.8 · Published 2026-09-15

Technologies: github.com/sylabs/singularity (Go). Vendors: Go.

Executive brief

Singularity is a container platform often used in high-performance computing environments. A security flaw in its configuration handling allows users to run containers from unauthorized directories if those directories have names that start with the same characters as an authorized path. This bypasses administrative restrictions intended to ensure only trusted software is executed in sensitive environments.

Technical details

A path traversal/incorrect matching vulnerability (CWE-22) exists in Singularity's 'limit container paths' directive within singularity.conf. When operating in setuid mode, the runtime performs string-based prefix matching rather than strict directory boundary matching. An attacker with local access can bypass execution restrictions by placing container images in sibling directories that share a prefix with an allowed path (e.g., '/data/safe-unauthorized' matching a rule for '/data/safe'). This allows for the execution of unauthorized containers in environments where path-based restrictions are enforced. The issue is resolved in SingularityCE 4.4.2 and SingularityPRO 4.3.9 / 4.1.14.

Affected products

  • Sylabs SingularityCE < 4.4.2, <= 3.1.1
  • Sylabs SingularityPRO < 4.3.9, < 4.1.14

Timeline

  • 2026-06-04: disclosed
  • 2026-06-04: advisory
  • 2026-06-04: patched

References

Related threats