{"id":"CVE-2026-47261","aliases":["GHSA-2r75-cxrj-cmph","RUSTSEC-2026-0149"],"url":"https://o3.security/vulnerability/CVE-2026-47261","summary":"Wasmtime: WASI path_open(TRUNCATE) bypasses `FilePerms::WRITE` host restriction","details":"## Summary\n\nIn `wasmtime-wasi`, when a filesystem preopen is given `DirPerms::all()` and `FilePerms::READ` without `FilePerms::WRITE`,  this wasmtime-wasi enforced access control mechanism can be bypassed by using the wasip2 `descriptor.open-at` or wasip1 `path_open` interfaces by opening a file with `OpenFlags::TRUNCATE` oflag only, for example:\n\n```rust\ndir_descriptor.open_at(\n   PathFlags::empty(),\n   FILENAME,\n   OpenFlags::TRUNCATE,\n   DescriptorFlags::READ,\n)\n```\n\n```rust\nwasip1::path_open(\n    dir_fd,\n    0,\n    FILENAME,\n    wasip1::OFLAGS_TRUNC,\n    wasip1::RIGHTS_FD_READ,\n    0,\n    0\n)\n```\n\nThe root cause is that the clause that considered `OpenFlags::TRUNCATE` did not set `open_mode |= OpenMode::WRITE;`, used later in that function for the access control check against `FilePerms` for whether opening that file is permitted. With the bug corrected, these calls to `open-at` and `path_open` fail with `error-code.not-permitted` and `ERRNO_PERM` respectively.\n\nThe bug in `crates/wasi/src/filesystem.rs`, `Dir::open_at`, lines 967–969:\n\n```rust\nif oflags.contains(OpenFlags::TRUNCATE) {\n    opts.truncate(true).write(true);\n}\n```\nand the single line fix is:\n```rust\nif oflags.contains(OpenFlags::TRUNCATE) {\n    opts.truncate(true).write(true);\n    open_mode |= OpenMode::WRITE;\n}\n```\n\nOnly wasmtime-wasi embeddings that use a combination of DirPerms::MUTATE with FilePerms::READ are affected by this bug, e.g. those that use in the `WasiCtxBuilder`:\n```rust\nbuilder.preopened_dir(\"readonly\", \"readonly\", DirPerms::READ | DirPerms::MUTATE, FilePerms::READ);\n```\n\nIn particular, the Wasmtime project's `wasmtime-cli`'s use of wasmtime-wasi is not affected, because it always sets `FilePerms::all()` for all preopens.","published":"2026-06-15T19:47:40.366Z","modified":"2026-08-12T03:51:31.300841236Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":{"score":0.00357,"percentile":0.2889,"asOf":"2026-08-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"wasmtime-wasi","fixedVersion":"44.0.2"},{"ecosystem":"crates.io","name":"wasmtime-wasi","fixedVersion":"36.0.10"},{"ecosystem":"crates.io","name":"wasmtime-wasi","fixedVersion":"24.0.9"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/bytecodealliance/wasmtime/releases/tag/v24.0.9"},{"type":"WEB","url":"https://github.com/bytecodealliance/wasmtime/releases/tag/v36.0.10"},{"type":"WEB","url":"https://github.com/bytecodealliance/wasmtime/releases/tag/v44.0.2"},{"type":"WEB","url":"https://github.com/bytecodealliance/wasmtime/releases/tag/v45.0.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47261.json"},{"type":"ADVISORY","url":"https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-2r75-cxrj-cmph"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47261"},{"type":"PACKAGE","url":"https://github.com/bytecodealliance/wasmtime"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2026-0149.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:31.300841236Z"}}