
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69820 is a Directory Traversal vulnerability in Beam beta9 v.0.1.521 (also referenced as v.0.1.552 in earlier CVE descriptions) that allows a remote attacker with high privileges to read or modify sensitive information via the joinCleanPath function in the volume multipart upload module. The vulnerability was published on January 22, 2026, and classified under CWE-22. It carries a CVSS v3.1 base score of 6.0 (Medium), with local attack vector, low complexity, and high privileges required (Red Hat CVE, NVD).
The root cause (CWE-22) lies in the joinCleanPath function defined in pkg/abstractions/volume/multipart.go (line 45), which applies filepath.Clean and filepath.Join to user-supplied VolumePath values before constructing S3 object keys for presigned URLs. Because filepath.Clean resolves ../ sequences, a crafted VolumePath such as ../../other-workspace/secret.txt causes the resulting S3 key to escape the intended workspace prefix (e.g., volumes/workspace-a/vol-1) and point to an object in a different workspace or bucket path. This flaw affects the CreatePresignedURL, CreateMultipartUpload, CompleteMultipartUpload, and AbortMultipartUpload RPC handlers, all of which pass user input through joinCleanPath before issuing S3 operations (beta9 source, PoC repo).
A successfully exploited attacker can generate presigned S3 URLs that reference objects outside their authorized workspace, enabling unauthorized GET (read) or PUT (write/overwrite) access to cloud-stored files belonging to other workspaces or tenants. This poses a significant risk to data confidentiality and integrity — sensitive files could be exfiltrated or maliciously overwritten — while availability is not directly impacted. In multi-tenant Beam deployments, cross-workspace data access represents a meaningful lateral movement risk within the shared S3 bucket (PoC repo, Red Hat CVE).
A proof-of-concept demonstrating the path traversal via joinCleanPath is publicly available on GitHub, published by researcher ryotaromatsui (PoC repo). Exploitation requires local access and high privilege level (authenticated user with elevated permissions), which limits the attack surface. There is no evidence of in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.0027 (0.27%), indicating low probability of near-term exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
volumes/<workspace-name>/<volume-external-id>/).VolumePath value containing path traversal sequences, such as ../../other-workspace/<target-volume-id>/secret.txt, designed to escape the current workspace prefix after joinCleanPath normalization.CreatePresignedURLRequest with the malicious VolumePath and desired method (GetObject for read, PutObject for write) to the GlobalVolumeService.CreatePresignedURL endpoint.joinCleanPath, resolving ../ sequences and producing an S3 key pointing to the target object outside the authorized workspace (e.g., volumes/other-workspace/<target-volume-id>/secret.txt).volumes/<different-workspace>/ in the URL path).CreatePresignedURL or CreateMultipartUpload RPC calls with VolumePath values containing ../ sequences; S3 access logs recording object access under workspace prefixes not matching the requesting workspace's name or external ID.VolumePath values suggesting enumeration of cross-workspace paths (PoC repo).No official patch or fixed version has been announced by the Beam beta9 project as of the time of this report. Recommended interim mitigations include: (1) restricting access to the CreatePresignedURL and multipart upload RPC endpoints to only trusted, necessary users; (2) implementing server-side input validation to reject VolumePath values containing ../ or other traversal sequences before passing them to joinCleanPath; (3) replacing joinCleanPath with logic that validates the final resolved path remains within the expected workspace prefix; and (4) monitoring S3 access logs for cross-workspace object access patterns. Users should follow the Beam beta9 GitHub repository for patch releases (beta9 source, Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."