Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-48722— Nextflow: Incorrect default permissions in the nextflow auth login command

Quick assessment

Affected
nextflow-io nextflow
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Nextflow 是一种用于数据驱动计算流水线的领域特定语言(DSL)。在 25.09.2-edge 至 25.10.6 以及 26.04.3 版本中, 命令会通过 中的 方法,将 Seqera Platform 的 OIDC Bearer Token 写入 文件,但在写入过程中未设置严格的文件权限。由于默认 umask 值为 022,该文件将以 0644 权限创建(即所有者可读写,其他用户可读)。在多用户 POSIX 系统上,任何能够遍历受害者主目录的本地用户均可读取 文件,并在令牌的有效范围内冒充受害者访问 S

CVSS 5.5 · Medium EPSS 0.10% · P1

Affected Version Matrix 2

VendorProduct Version RangeStatus
nextflow-io nextflow >= 25.09.2-edge, < 25.10.6 affected
>= 25.11.0-edge, < 26.04.3 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-48722

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Nextflow: Incorrect default permissions in the nextflow auth login command
Source: CVE Program / CVE List V5
Vulnerability Description
Nextflow is a DSL for data-driven computational pipelines. From 25.09.2-edge until 25.10.6 and 26.04.3, nextflow auth login writes Seqera Platform OIDC bearer tokens to ${NXF_HOME:-~/.nextflow}/seqera-auth.config through AuthCommandImpl.writeConfig in plugins/nf-tower/src/main/io/seqera/tower/plugin/auth/AuthCommandImpl.groovy without setting restrictive file permissions, allowing the default umask 022 to create the file with mode 0644. On a multi-user POSIX host, a local user who can traverse the victim's home directory can read seqera-auth.config and impersonate the victim against Seqera Platform within the token's scope. Single-user systems and headless CI runners that do not use the interactive login flow are not affected. This issue is fixed in 25.10.6 and 26.04.3.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
缺省权限不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
nextflow-io nextflow >= 25.09.2-edge, < 25.10.6 -

II. Public POCs for CVE-2026-48722

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-48722

登录查看更多情报信息。

Patches & Fixes for CVE-2026-48722 (3)

Vendor Advisories for CVE-2026-48722 (1)

Vendor Pages for CVE-2026-48722 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-48722

No comments yet


Leave a comment