{"id":"GHSA-fgmf-7rf8-m6vf","summary":"ZITADEL: Actions V1 sandbox escape: host file read via require()","details":"### Summary\n\nA vulnerability in ZITADEL Actions V1 allows an organization Action author to read files from the ZITADEL host filesystem through the JavaScript `require()` module loader. On common self-hosted deployments this can be chained to steal bootstrap credentials (including the Login Client PAT) and escalate from a single-tenant organization owner to instance administrator.\n\n### Impact\n\nZITADEL Actions V1 run custom JavaScript inside the ZITADEL server process at OIDC, SAML, and login-flow trigger points. The runtime enables the goja Node-compatible `require()` registry without restricting the source loader, so Action scripts can load host files readable by the ZITADEL process (notably `.js` and `.json`, and in some cases other file contents via error channels).\n\nAn attacker with **ORG_OWNER** on any organization (which includes `org.action.write` and `org.flow.write`) can therefore:\n\n* Read process-readable host files, including configuration or secrets mounted into the API container (for example service-account material, projected secrets, or config carrying sensitive values).\n* On deployments that follow ZITADEL’s documented bootstrap paths (`ZITADEL_FIRSTINSTANCE_LOGINCLIENTPATPATH`, `ZITADEL_FIRSTINSTANCE_MACHINEKEYPATH`), recover instance-wide credentials such as the **IAM_LOGIN_CLIENT** PAT or the **IAM_OWNER** service-account key, enabling escalation to full instance control.\n\nThis collapses the expected multi-tenant isolation boundary: a tenant organization administrator is not meant to access host filesystem secrets or instance-wide credentials.\n\n**Scope note:** This issue affects **Actions V1**. Host command execution was not identified as part of this vulnerability. Impact depends on what the ZITADEL process can read on disk and on deployment layout — documented Compose and quick-start setups that write bootstrap PATs or machine keys into the API container amplify severity.\n\n### Affected Versions\n\nSystems running one of the following versions are affected:\n\n* **4.x:** `4.0.0` through `4.16.0` (including RC versions)\n* **3.x:** `3.0.0` through `3.4.12` (including RC versions)\n\n### Patches\n\nThe vulnerability has been addressed in the latest releases. The patch disables filesystem-backed module loading for Action scripts so that only the intended native `zitadel/*` modules can be required.\n\n* **4.x**: Upgrade to $\\ge$ [4.16.1](https://github.com/zitadel/zitadel/releases/tag/v4.16.1)\n* **3.x**: Upgrade to $\\ge$ [3.4.13](https://github.com/zitadel/zitadel/releases/tag/v3.4.13)\n\n### Workarounds\n\nIf an immediate upgrade is not possible:\n\n* Restrict who can create, update, or attach Actions — do not grant `org.action.write` / `org.flow.write` (or **ORG_OWNER**) to untrusted administrators in multi-tenant environments.\n* Audit existing Actions for `require()` of filesystem paths.\n* Remove or relocate bootstrap credential files (`login-client.pat`, machine keys) so they are not readable inside the API process filesystem.\n* Limit host filesystem exposure for the ZITADEL process (no unnecessary readable secrets beside the binary).\n\n### Questions\n\nIf you have any questions or comments about this advisory, please email us at [security@zitadel.com](mailto:security@zitadel.com)\n\n### Credits\n\nThanks to Dor Konis ([@dkonis](https://github.com/dkonis)) and Feras Daragma ([@FerasTr](https://github.com/FerasTr)) from GE Vernova, and to [pyuysig](https://github.com/pyuysig), for finding and reporting this vulnerability.","aliases":["CVE-2026-85057"],"modified":"2026-09-24T18:30:08.446129402Z","published":"2026-09-24T18:19:32Z","database_specific":{"github_reviewed_at":"2026-09-24T18:19:32Z","nvd_published_at":null,"cwe_ids":["CWE-284"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/zitadel/zitadel/security/advisories/GHSA-fgmf-7rf8-m6vf"},{"type":"WEB","url":"https://github.com/zitadel/zitadel/commit/afe108640cf57a17e8b743fbcdad9ae636eb3eb7"},{"type":"WEB","url":"https://github.com/zitadel/zitadel/commit/baf6ed501b684f47048553d9034e8d3aa824950e"},{"type":"WEB","url":"https://github.com/zitadel/zitadel/commit/e28d6bcc033368c3e9683ee15c195b8460b9305d"},{"type":"PACKAGE","url":"https://github.com/zitadel/zitadel"},{"type":"WEB","url":"https://github.com/zitadel/zitadel/releases/tag/v3.4.13"},{"type":"WEB","url":"https://github.com/zitadel/zitadel/releases/tag/v4.16.1"}],"affected":[{"package":{"name":"github.com/zitadel/zitadel","ecosystem":"Go","purl":"pkg:golang/github.com/zitadel/zitadel"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.80.0-v2.20.0.20260717062331-baf6ed501b68"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-fgmf-7rf8-m6vf/GHSA-fgmf-7rf8-m6vf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N"}]}