GHSA-rh99-wc69-c255
### Impact The [Kata agent policies](https://docs.edgeless.systems/contrast/architecture/components/policies) generated by the Contrast CLI had an issue in the `CopyFile` verification, which allowed arbitrary writes to the guest root filesytem. A malicious process on the host with the capability to connect to the Kata agent VSOCK could connect to the agent and issue a series of `CopyFile` requests to overwrite security-critical files or trick the workload into disclosing sensitive data, which effectively amounts to a full guest takeover. ### Patches This issue has been patched in Contrast v1.19.1. Note that this fix does not change the fact that host-provided content is generally not trustworthy, as documented. ### Workarounds If upgrading is not possible, users can implement the fix in rego and pass it to `contrast generate --policy`. The rego-only fix is a bit trickier than the patch, because the data to check is binary. See the references for details. ### Resources * Upstream GHSA: https://github.com/kata-containers/kata-containers/security/advisories/GHSA-q49m-57vm-c8cc * Alternative policy-only fix: https://gist.github.com/burgerdev/304dd0ab0fff1665b7c27e18a30cf96e
Properties
- ghsa_id
- GHSA-rh99-wc69-c255
- severity
- high
- summary
- Contras Affected by CopyFile Policy Subversion via Symlinks
- cvss_score
- 8.1
- cve_id
- GHSA-rh99-wc69-c255
- cvss_vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- is_ghsa_only
- true
- ghsa_published
- 2026-04-30T20:57:17Z
- source_url
- https://github.com/advisories/GHSA-rh99-wc69-c255
- ghsa_updated
- 2026-04-30T20:57:19Z
Related Entities (4)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph