Configuration loader builds a path before validating the tunnel name
Fixed in: v1.1; recorded as defensive validation, not a confirmed reachable exploit
details
- Finding IDs
- F-WIREGUARD-001-001
- Status
- fixed publicly
- Fixed in
- v1.1; recorded as defensive validation, not a confirmed reachable exploit
- Note
- LoadFromName constructed a configuration path from a supplied tunnel name without first calling TunnelNameIsValid. The 3 May 2026 patch adds that validation before path construction and rejects invalid names. The guard is present in v1.1 and absent from the inspected v1.0.1 source. The maintainer describes the path as not really reachable and the change as a missing defensive check. This record therefore documents matching source hardening, not acceptance of a HIGH-severity vulnerability, a confirmed unprivileged attack path, or attribution of the patch to this report. Public-source review does not establish vendor attribution, an assigned severity or a fresh end-to-end retest.
F-WIREGUARD-001-001: File / path escapes. A tunnel-name-to-path conversion lacks a local name-validation boundary; the upstream fix adds it defensively. Reviewed 26 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-WIREGUARD-001-001
Security area (1seal assessment): Authorization. A tunnel-name-to-path conversion lacks a local name-validation boundary; the upstream fix adds it defensively. Reviewed 26 Sep 2026.