6.9 MEDIUM
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): High (H)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): High (H)
- Vulnerable System Impact Integrity (VI): None (N)
- Vulnerable System Impact Availability (VA): None (N)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): High (H)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): High (H)
- Modified Vulnerable System Impact Integrity (MVI): None (N)
- Modified Vulnerable System Impact Availability (MVA): None (N)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
Activity log
- Created suggestion
MinIO: Path Traversal via msgpack Body in `ReadMultiple` Storage-REST Endpoint
MinIO is a high-performance object storage system. From RELEASE.2022-07-24T01-54-52Z to before RELEASE.2026-04-14T21-32-45Z, A path traversal vulnerability in MinIO's ReadMultiple internode storage-REST endpoint allows a caller holding the cluster root JWT to read files from outside the configured drive roots, bounded only by the MinIO process UID. The attacker sends POST minio/storage/{drivePath}/v63/rmpl with a msgpack-encoded body carrying ../ sequences in the Bucket field. The server opens the resulting path via os.OpenFile with O_RDONLY|O_NOATIME and returns its contents in the msgpack response stream. This vulnerability is fixed in RELEASE.2026-04-14T21-32-45Z.
References
-
https://github.com/minio/minio/security/advisories/GHSA-xh8f-g2qw-gcm7 x_refsource_CONFIRM
Affected products
- ==>= RELEASE.2022-07-24T01-54-52Z, < RELEASE.2026-04-14T21-32-45Z
Matching in nixpkgs
pkgs.minio
S3-compatible object storage server
-
nixos-unstable 2025-10-15T17-29-55Z
- nixpkgs-unstable 2025-10-15T17-29-55Z
- nixos-unstable-small 2025-10-15T17-29-55Z
pkgs.minion
Addon manager for World of Warcraft and The Elder Scrolls Online
pkgs.kminion
Feature-rich Prometheus exporter for Apache Kafka written in Go
pkgs.minio-cpp
MinIO C++ Client SDK for Amazon S3 Compatible Cloud Storage
pkgs.minio-warp
S3 benchmarking tool
pkgs.minio-client
Replacement for ls, cp, mkdir, diff and rsync commands for filesystems and object storage
-
nixos-unstable 2025-08-13T08-35-41Z
- nixpkgs-unstable 2025-08-13T08-35-41Z
- nixos-unstable-small 2025-08-13T08-35-41Z
pkgs.minio-certgen
Simple Minio tool to generate self-signed certificates, and provides SAN certificates with DNS and IP entries
pkgs.minio_legacy_fs
None
pkgs.perlPackages.Minion
High performance job queue for Perl
pkgs.perl5Packages.Minion
High performance job queue for Perl
pkgs.haskellPackages.minion
A Haskell introspectable web router
pkgs.perl538Packages.Minion
None
pkgs.perl540Packages.Minion
None
pkgs.python312Packages.minio
None
pkgs.python313Packages.minio
Simple APIs to access any Amazon S3 compatible object storage server
pkgs.python314Packages.minio
Simple APIs to access any Amazon S3 compatible object storage server
pkgs.haskellPackages.minio-hs
A MinIO Haskell Library for Amazon S3 compatible cloud storage
pkgs.terraform-providers.minio
None
pkgs.haskellPackages.minion-jwt
Minion JWT support
pkgs.haskellPackages.minion-htmx
Minion HTMX support
pkgs.haskellPackages.minion-conduit
Minion conduit support
pkgs.haskellPackages.minion-openapi3
Minion openapi3 support
-
nixos-unstable openapi3-0.1.0.1
- nixpkgs-unstable openapi3-0.1.0.1
- nixos-unstable-small openapi3-0.1.0.1
pkgs.perlPackages.MinionBackendRedis
Redis backend for Minion job queue
pkgs.perlPackages.MinionBackendmysql
MySQL backend for the Minion job queue
pkgs.haskellPackages.minion-wai-extra
Minion wrappers for wai-extra
pkgs.perl5Packages.MinionBackendRedis
Redis backend for Minion job queue
pkgs.perl5Packages.MinionBackendmysql
MySQL backend for the Minion job queue
pkgs.perlPackages.MinionBackendSQLite
SQLite backend for Minion job queue
pkgs.perl5Packages.MinionBackendSQLite
SQLite backend for Minion job queue
pkgs.perl538Packages.MinionBackendRedis
None
pkgs.perl538Packages.MinionBackendmysql
None
pkgs.perl540Packages.MinionBackendRedis
None
pkgs.perl540Packages.MinionBackendmysql
None
pkgs.terraform-providers.aminueza_minio
None
pkgs.perl538Packages.MinionBackendSQLite
None
pkgs.perl540Packages.MinionBackendSQLite
None
pkgs.home-assistant-component-tests.minio
None
Package maintainers
-
@mpscholten Marc Scholten <marc@digitallyinduced.com>
-
@cafkafk Christina Sørensen <christina@cafkafk.com>
-
@ryan4yin Ryan Yin <xiaoyin_c@qq.com>
-
@bachp Pascal Bach <pascal.bach@nextrem.ch>
-
@roquess Steve Roques <steve.roques@gmail.com>
-
@drupol Pol Dellaiera <pol.dellaiera@protonmail.com>
-
@cyrusknopf Cyrus Knopf <cyrus.knopf@gmail.com>
-
@christoph-heiss Christoph Heiss <christoph@c8h4.io>
-
@PatrickDaG Patrick <patrick-nixos@failmail.dev>
-
@stigtsp Stig Palmquist <stig@stig.io>
-
@TomaSajt TomaSajt