Executive brief
The BOSH CLI tool, used for managing large-scale cloud deployments, contains a security flaw in how it handles configuration files. An attacker could exploit this to write malicious files to a user's system or steal sensitive information. This could lead to a full system compromise or the exposure of credentials used to manage cloud infrastructure.
Technical details
A path traversal vulnerability exists in the BOSH CLI tool's handling of the 'path' key within 'blobs.yml' files. By crafting a malicious configuration file, an attacker can bypass directory restrictions to write files to arbitrary locations on the local filesystem or exfiltrate sensitive data. The attack requires minimal user interaction (UI:R), such as a user running a BOSH command against a malicious repository or configuration. The vulnerability is addressed in BOSH CLI version 7.10.4.
Affected products
- CloudFoundry Foundation BOSH CLI tool prior to v7.10.4
Timeline
- 2026-07-08: advisory: Initial vulnerability report published by Cloud Foundry Foundation
- 2026-07-09: disclosed: CVE published to NVD dataset