{"id":"BIT-seaweedfs-2026-72921","summary":"SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths","details":"SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes authorization check used strings.HasPrefix on raw path strings, so a filer JWT scoped to /tenant1 also authorized sibling paths such as /tenant1234, /tenant1-old, and /tenant1backup, enabling cross-tenant reads and writes with a valid scoped token. This issue is fixed in version 4.24.","aliases":["CVE-2026-72921","GHSA-gv5w-hfx8-8cwq","GO-2026-6361"],"modified":"2026-09-10T15:25:58.234708514Z","published":"2026-08-17T05:54:17.400Z","database_specific":{"severity":"High","cpes":["cpe:2.3:a:seaweedfs:seaweedfs:*:*:*:*:*:go:*:*"]},"references":[{"type":"WEB","url":"https://github.com/seaweedfs/seaweedfs/commit/05ed5c9ae8a2a45101b52b61d02f170d20d587ff"},{"type":"WEB","url":"https://github.com/seaweedfs/seaweedfs/pull/9439"},{"type":"WEB","url":"https://github.com/seaweedfs/seaweedfs/releases/tag/4.24"},{"type":"WEB","url":"https://github.com/seaweedfs/seaweedfs/security/advisories/GHSA-gv5w-hfx8-8cwq"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72921"}],"affected":[{"package":{"name":"seaweedfs","ecosystem":"Bitnami","purl":"pkg:bitnami/seaweedfs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.24.0"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/seaweedfs/BIT-seaweedfs-2026-72921.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"}]}],"schema_version":"1.9.0"}