{"id":"CVE-2025-3047","aliases":["GHSA-px37-jpqx-97q9","PYSEC-2026-1207"],"url":"https://o3.security/vulnerability/CVE-2025-3047","summary":"Path Traversal in AWS SAM CLI allows file copy to build container","details":"When running the AWS Serverless Application Model Command Line Interface (SAM CLI) build process with Docker and symlinks are included in the build files, the container environment allows a user to access privileged files on the host by leveraging the elevated permissions granted to the tool. A user could leverage the elevated permissions to access restricted files via symlinks and copy them to a more permissive location on the container. \n\nUsers should upgrade to v1.133.0 or newer and ensure any forked or derivative code is patched to incorporate the new fixes.","published":"2025-03-31T15:21:11.290Z","modified":"2026-07-15T01:49:05.228485265Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"aws-sam-cli","fixedVersion":"1.133.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://aws.amazon.com/security/security-bulletins/AWS-2025-008/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/3xxx/CVE-2025-3047.json"},{"type":"ADVISORY","url":"https://github.com/aws/aws-sam-cli/security/advisories/GHSA-px37-jpqx-97q9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-3047"},{"type":"FIX","url":"https://github.com/aws/aws-sam-cli/releases/tag/v1.134.0"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:05.228485265Z"}}