MEDIUMCVSS 5.5Vulnerability

CVE-2026-73974

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses its shared testing helper across check plugins. Prior to linuxfabrik-lib 6.1.0 and Linuxfabrik Monitoring Plugins 7.0.0, lib.lftest.test() treated the first or second element of a --test CSV argument as a filesystem path and returned the file contents as simulated standard output or standard error without path confinement. The hidden but production-accessible --test argument was accepted by sudo-authorized plugins, so an attacker controlling the nagios or icinga account could use check-plugins/deb-updates/deb-updates with its default QUERY=1 to disclose every line of a root-readable file. Approximately 22 other plugins exposed filtered content or a root file existence and readability oracle through the same helper, while check-plugins/network-bonding/network-bonding and check-plugins/openstack-swift-stat/openstack-swift-stat had direct read paths that bypassed the helper. The library fix confines fixture reads to the invoking plugin's unit-test directory and refuses unsafe anchors, and the plugin fix routes the two bypasses through that helper. These issues are fixed in linuxfabrik-lib 6.1.0 and Linuxfabrik Monitoring Plugins 7.0.0.

Properties

summary
linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)
severity
MEDIUM
cvss_severity
MEDIUM
epss_score
0.00168
cvss_score
5.5
retrieved_at
2026-10-02T19:34:42+00:00
ghsa_published
2026-08-18T21:18:59Z
source_url
https://github.com/advisories/GHSA-rh9c-rqvg-f7pr
ghsa_updated
2026-08-18T21:19:01Z
ghsa_id
GHSA-rh9c-rqvg-f7pr
last_source
FIRST EPSS
score
5.5
cve_id
CVE-2026-73974
cvss_vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
signal_observed_at
2026-09-11T17:54:58+00:00
is_ghsa_only
false
vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
published_at
2026-08-18T22:17:33.840
last_modified
2026-09-09T21:13:25.910
epss_percentile
0.05553

Related Entities (7)

DESCRIBED_BY (1)

→[Source]NVD

ENRICHED_BY (1)

→[Source]FIRST EPSS

VULNERABLE_TO (1)

←[Software]pip/linuxfabrik-lib

AFFECTS (1)

→[Software]pip/linuxfabrik-lib

HAS_WEAKNESS (2)

→[Weakness]Improper Privilege Management
→[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph