Path traversal in `sops exec-file --filename` leaks decrypted plaintext outside temporary directory
Fixed in: sops 3.13.0
details
- Finding IDs
- F-MOZILLA-SOPS-002
- GHSA
- GHSA-x4cm-pcq4-39j4
- Status
- patched
- Fixed in
- sops 3.13.0
- Note
- exec-file --filename rejects non-local paths so decrypted plaintext cannot escape the temporary-directory cleanup boundary; fixed via PR #2155.
- Upstream title
- Path traversal in `sops exec-file --filename` leaks decrypted plaintext outside temporary directory
- Upstream publication
- Upstream updated
- Metadata fetched
- Upstream @1seal credit
- @1seal: reporter (accepted)
F-MOZILLA-SOPS-002: File / path escapes. A non-local exec-file filename escapes temporary-file cleanup. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-MOZILLA-SOPS-002
Security area (1seal assessment): Confidentiality. Decrypted plaintext can remain outside the temporary directory and its cleanup, exposing secret content to later readers. Reviewed 24 Sep 2026.