openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 contain a path traversal flaw in PluginSandbox._is_safe_path, which authorized file access using a bare string-prefix match. A sandboxed plugin without the READ_FILES permission could read or write another plugin's directory that merely shares a name prefix (e.g., .../plugins/foobar matching allowed .../plugins/foo), breaking per-plugin isolation within the same user. Fixed by matching each allowed directory exactly or with a trailing path separator.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Sep 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:jahlives:openssl_encrypt:*:*:*:*:*:python:*:* |
Thu, 27 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jahlives
Jahlives openssl Encrypt |
|
| Vendors & Products |
Jahlives
Jahlives openssl Encrypt |
Thu, 27 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 contain a path traversal flaw in PluginSandbox._is_safe_path, which authorized file access using a bare string-prefix match. A sandboxed plugin without the READ_FILES permission could read or write another plugin's directory that merely shares a name prefix (e.g., .../plugins/foobar matching allowed .../plugins/foo), breaking per-plugin isolation within the same user. Fixed by matching each allowed directory exactly or with a trailing path separator. | |
| Title | openssl_encrypt before 1.4.9 Plugin Sandbox Path Traversal | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-08-27T14:51:11.331Z
Updated: 2026-08-27T19:28:26.155Z
Reserved: 2026-08-27T11:13:14.063Z
Link: CVE-2026-81716
No data.
Status : Analyzed
Published: 2026-08-27T17:21:01.877
Modified: 2026-09-02T13:09:05.350
Link: CVE-2026-81716
No data.