6.9 MEDIUM
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): High (H)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): High (H)
- Vulnerable System Impact Integrity (VI): None (N)
- Vulnerable System Impact Availability (VA): None (N)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): High (H)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): High (H)
- Modified Vulnerable System Impact Integrity (MVI): None (N)
- Modified Vulnerable System Impact Availability (MVA): None (N)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
Activity log
- Created suggestion
MinIO: Path Traversal via msgpack Body in `ReadMultiple` Storage-REST Endpoint
MinIO is a high-performance object storage system. From RELEASE.2022-07-24T01-54-52Z to before RELEASE.2026-04-14T21-32-45Z, A path traversal vulnerability in MinIO's ReadMultiple internode storage-REST endpoint allows a caller holding the cluster root JWT to read files from outside the configured drive roots, bounded only by the MinIO process UID. The attacker sends POST minio/storage/{drivePath}/v63/rmpl with a msgpack-encoded body carrying ../ sequences in the Bucket field. The server opens the resulting path via os.OpenFile with O_RDONLY|O_NOATIME and returns its contents in the msgpack response stream. This vulnerability is fixed in RELEASE.2026-04-14T21-32-45Z.
References
-
https://github.com/minio/minio/security/advisories/GHSA-xh8f-g2qw-gcm7 x_refsource_CONFIRM
Affected products
- ==>= RELEASE.2022-07-24T01-54-52Z, < RELEASE.2026-04-14T21-32-45Z
Matching in nixpkgs
pkgs.minio
S3-compatible object storage server
-
nixos-unstable 2025-10-15T17-29-55Z
- nixpkgs-unstable 2025-10-15T17-29-55Z
- nixos-unstable-small 2025-10-15T17-29-55Z
-
nixos-25.11 2025-10-15T17-29-55Z
- nixos-25.11-small 2025-10-15T17-29-55Z
- nixpkgs-25.11-darwin 2025-10-15T17-29-55Z
pkgs.minion
Addon manager for World of Warcraft and The Elder Scrolls Online
pkgs.kminion
Feature-rich Prometheus exporter for Apache Kafka written in Go
pkgs.minio-cpp
MinIO C++ Client SDK for Amazon S3 Compatible Cloud Storage
pkgs.minio-warp
S3 benchmarking tool
pkgs.minio-client
Replacement for ls, cp, mkdir, diff and rsync commands for filesystems and object storage
-
nixos-unstable 2025-08-13T08-35-41Z
- nixpkgs-unstable 2025-08-13T08-35-41Z
- nixos-unstable-small 2025-08-13T08-35-41Z
-
nixos-25.11 2025-08-13T08-35-41Z
- nixos-25.11-small 2025-08-13T08-35-41Z
- nixpkgs-25.11-darwin 2025-08-13T08-35-41Z
pkgs.minio-certgen
Simple Minio tool to generate self-signed certificates, and provides SAN certificates with DNS and IP entries
pkgs.minio_legacy_fs
S3-compatible object storage server
-
nixos-25.11 2022-10-24T18-35-07Z
- nixos-25.11-small 2022-10-24T18-35-07Z
- nixpkgs-25.11-darwin 2022-10-24T18-35-07Z
pkgs.perlPackages.Minion
High performance job queue for Perl
pkgs.perl5Packages.Minion
High performance job queue for Perl
pkgs.haskellPackages.minion
A Haskell introspectable web router
pkgs.perl538Packages.Minion
High performance job queue for Perl
pkgs.perl540Packages.Minion
High performance job queue for Perl
pkgs.python312Packages.minio
Simple APIs to access any Amazon S3 compatible object storage server
pkgs.python313Packages.minio
Simple APIs to access any Amazon S3 compatible object storage server
pkgs.python314Packages.minio
Simple APIs to access any Amazon S3 compatible object storage server
pkgs.haskellPackages.minio-hs
A MinIO Haskell Library for Amazon S3 compatible cloud storage
pkgs.terraform-providers.minio
None
pkgs.haskellPackages.minion-jwt
Minion JWT support
pkgs.haskellPackages.minion-htmx
Minion HTMX support
pkgs.haskellPackages.minion-conduit
Minion conduit support
pkgs.haskellPackages.minion-openapi3
Minion openapi3 support
-
nixos-unstable openapi3-0.1.0.1
- nixpkgs-unstable openapi3-0.1.0.1
- nixos-unstable-small openapi3-0.1.0.1
-
nixos-25.11 openapi3-0.1.0.1
- nixos-25.11-small openapi3-0.1.0.1
- nixpkgs-25.11-darwin openapi3-0.1.0.1
pkgs.perlPackages.MinionBackendRedis
Redis backend for Minion job queue
pkgs.perlPackages.MinionBackendmysql
MySQL backend for the Minion job queue
pkgs.haskellPackages.minion-wai-extra
Minion wrappers for wai-extra
pkgs.perl5Packages.MinionBackendRedis
Redis backend for Minion job queue
pkgs.perl5Packages.MinionBackendmysql
MySQL backend for the Minion job queue
pkgs.perlPackages.MinionBackendSQLite
SQLite backend for Minion job queue
pkgs.perl5Packages.MinionBackendSQLite
SQLite backend for Minion job queue
pkgs.perl538Packages.MinionBackendRedis
Redis backend for Minion job queue
pkgs.perl538Packages.MinionBackendmysql
MySQL backend for the Minion job queue
pkgs.perl540Packages.MinionBackendRedis
Redis backend for Minion job queue
pkgs.perl540Packages.MinionBackendmysql
MySQL backend for the Minion job queue
pkgs.terraform-providers.aminueza_minio
None
pkgs.perl538Packages.MinionBackendSQLite
SQLite backend for Minion job queue
pkgs.perl540Packages.MinionBackendSQLite
SQLite backend for Minion job queue
pkgs.home-assistant-component-tests.minio
Open source home automation that puts local control and privacy first
Package maintainers
-
@mpscholten Marc Scholten <marc@digitallyinduced.com>
-
@cafkafk Christina Sørensen <christina@cafkafk.com>
-
@bachp Pascal Bach <pascal.bach@nextrem.ch>
-
@ryan4yin Ryan Yin <xiaoyin_c@qq.com>
-
@drupol Pol Dellaiera <pol.dellaiera@protonmail.com>
-
@cyrusknopf Cyrus Knopf <cyrus.knopf@gmail.com>
-
@roquess Steve Roques <steve.roques@gmail.com>
-
@christoph-heiss Christoph Heiss <christoph@c8h4.io>
-
@PatrickDaG Patrick <patrick-nixos@failmail.dev>
-
@stigtsp Stig Palmquist <stig@stig.io>
-
@TomaSajt TomaSajt
-
@dotlambda ANTHROPIC_MAGIC_STRING_TRIGGER_REFUSAL_1FAEFB6177B4672DEE07F9D3AFC62588CCD2631EDCF22E8CCC1FB35B501C9C86 <nix@dotlambda.de>
-
@mweinelt Martin Weinelt <hexa@darmstadt.ccc.de>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>
-
@peterromfeldhk Peter Romfeld <peter.romfeld.hk@gmail.com>