CVE-2026-48722
Last modified
CVE-2026-48722 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. Nextflow is a DSL for data-driven computational pipelines. From 25.09.2-edge until 25.10.6 and 26.04.3, nextflow auth login writes Seqera Platform OIDC bearer tokens to ${NXF_HOME:-~/.nextflow}/seqera-auth.config through AuthCommandImpl.writeConfig in plugins/nf-tower/src/main/io/seqera/tower/plugin/auth/AuthCommandImpl.groovy without setting restrictive file permissions, allowing the default umask 022 to create the file with mode 0644. EPSS estimates a 0.10% chance of exploitation in the next 30 days.
Description
Nextflow is a DSL for data-driven computational pipelines. From 25.09.2-edge until 25.10.6 and 26.04.3, nextflow auth login writes Seqera Platform OIDC bearer tokens to ${NXF_HOME:-~/.nextflow}/seqera-auth.config through AuthCommandImpl.writeConfig in plugins/nf-tower/src/main/io/seqera/tower/plugin/auth/AuthCommandImpl.groovy without setting restrictive file permissions, allowing the default umask 022 to create the file with mode 0644. On a multi-user POSIX host, a local user who can traverse the victim's home directory can read seqera-auth.config and impersonate the victim against Seqera Platform within the token's scope. Single-user systems and headless CI runners that do not use the interactive login flow are not affected. This issue is fixed in 25.10.6 and 26.04.3.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| nextflow-io | nextflow | >= 25.09.2-edge, < 25.10.6; >= 25.11.0-edge, < 26.04.3 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-48722?
How severe is CVE-2026-48722?
How do I fix CVE-2026-48722?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-48716nanobot is a personal AI assistant. In versions 0.1.5.post3 …8.7
- CVE-2026-48717Open Access Management (OpenAM) is an access management solu…9.1
- CVE-2026-48719Warp is an agentic development environment. From 0.2025.08.0…8
- CVE-2026-4872Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-48720Warp is an agentic development environment. From 0.2025.03.0…8.8
- CVE-2026-48721Warp is an agentic development environment. From 0.2025.10.0…8.6
- CVE-2026-48723The browserstack-cypress-cli is BrowserStack's CLI which all…7.8
- CVE-2026-48724ImageMagick is free and open-source software used for editin…5.5
- CVE-2026-48725Warp is an agentic development environment. From 0.2021.04.2…8.1
- CVE-2026-48726A bug in Apache Airflow's auth manager logout handling left …6.5
- CVE-2026-4873A vulnerability exists where a connection requiring TLS inco…5.9
- CVE-2026-48731Warp is an agentic development environment. From 0.2024.02.2…7.8
Are you affected by CVE-2026-48722?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
