SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-54917. PoCs published by BiiTts.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-54917, a path traversal vulnerability in SeaweedFS S3 gateway (<4.30) allowing cross-bucket unauthorized access via crafted `..` segments in object keys. The exploit demonstrates both read and write operations across buckets using SigV4-signed requests with traversal variants.
Description
SeaweedFS is a distributed storage system for object storage (S3), file systems, and Iceberg tables. Prior to 4.30, the S3 API gateway and the Iceberg REST catalog gateway construct their routers with mux.NewRouter().SkipClean(true). With path cleaning disabled, a .. segment inside the URL survives routing, so a request such as `GET /bucket-A/../evil-bucket/key`, is matched as bucket=bucket-A, object=../evil-bucket/key. The captured object key is then joined into a filer path with util.JoinPath (S3) / path.Join (Iceberg), which collapse the .. server-side, so the actual read or write lands in evil-bucket. This vulnerability is fixed in 4.30.
Exploits (1)
This repository contains a functional exploit for CVE-2026-54917, a path traversal vulnerability in SeaweedFS S3 gateway (<4.30) allowing cross-bucket unauthorized access via crafted `..` segments in object keys. The exploit demonstrates both read and write operations across buckets using SigV4-signed requests with traversal variants.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N