Executive brief
Chisel is a tool used to create secure tunnels for network traffic. A security flaw allows an authorized user to bypass access controls and connect to any network destination reachable by the Chisel server, rather than just the specific locations they were granted permission to access. This could allow an attacker to reach internal company resources or sensitive databases that should have been restricted.
Technical details
An authorization bypass exists in Chisel's server implementation where Access Control Lists (ACLs) defined in the --authfile are only validated during the initial SSH handshake. The root cause is that the user context and ACL restrictions are not propagated to the tunnel layer in 'share/tunnel/tunnel_out_ssh.go'. An attacker with valid credentials can authenticate using a permitted remote and then inject arbitrary 'host:port' destinations into the SSH channel's ExtraData field. The server accepts these subsequent channel requests unconditionally and dials the requested destination without further ACL checks. This allows a low-privileged authenticated user to reach any network resource accessible to the Chisel server process. The vulnerability is patched in version 1.11.5.
Affected products
- jpillora chisel <= 1.11.4
Timeline
- 2026-05-20: disclosed: Initial disclosure to vendor
- 2026-06-12: advisory: GitHub Advisory published
- 2026-06-12: patched: Version 1.11.5 released