
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24137 is a path traversal vulnerability in the legacy TUF client (pkg/tuf/client.go) of the sigstore Go framework, allowing a malicious TUF repository to trigger arbitrary file overwrites on affected systems. It affects github.com/sigstore/sigstore versions 1.10.3 and below; version 1.10.4 contains the fix. The vulnerability was published on January 22–23, 2026, and carries a CVSS v3.1 base score of 5.8 (Moderate) (Github Advisory, sigstore Advisory).
The root cause is CWE-22 (Path Traversal): the legacy TUF client's diskCache struct constructs filesystem paths by joining a cache base directory with a target name sourced directly from signed TUF metadata using filepath.Join, without validating that the resulting path remains within the intended cache directory. An attacker controlling a TUF repository can craft signed metadata containing target names with path traversal sequences (e.g., ../../../etc/passwd), causing the client to write arbitrary content to locations outside the cache directory. The fix in commit 8ec410a introduces a safePath() helper that applies url.PathEscape() to the target name before joining, neutralizing traversal sequences (sigstore Commit, Github Advisory).
Successful exploitation allows a malicious TUF repository to overwrite arbitrary files on the filesystem of the process running the vulnerable client, limited only by that process's OS-level permissions. This could enable an attacker to corrupt configuration files, replace binaries, or plant malicious content, potentially leading to privilege escalation or persistent compromise of the affected host. Confidentiality and availability are not directly impacted; the primary risk is integrity loss. Affected parties include direct consumers of the sigstore/sigstore TUF client library and users of older Cosign versions; public Sigstore deployment users are unaffected due to quorum-based metadata validation (sigstore Advisory, Github Advisory).
No public proof-of-concept exploit or evidence of in-the-wild exploitation has been reported as of the time of disclosure (Github Advisory). Exploitation requires the attacker to control or compromise a TUF repository that the victim client trusts, which represents a high-privilege precondition. The EPSS score is approximately 0.016% (4th percentile), indicating a very low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
../../../etc/cron.d/malicious or ../../../home/user/.ssh/authorized_keys, and sign it with valid TUF keys for the repository.sigstore/sigstore client (version ≤ 1.10.3) processes the metadata and attempts to cache the target file to disk, it calls filepath.Join(d.base, targetName) without sanitization, resolving the path outside the cache directory.~/.sigstore/root/targets/ or a custom SIGSTORE_CACHE_DIR); files with names containing URL-encoded traversal sequences (e.g., ..%2F) in the cache directory indicating attempted exploitation that was blocked by a patched version.os.MkdirAll or os.WriteFile in paths outside the expected cache base./etc/cron.d/, ~/.ssh/authorized_keys, system binaries) coinciding with sigstore/Cosign client invocations.Upgrade github.com/sigstore/sigstore to version 1.10.4 or later, which introduces path escaping via url.PathEscape() in the safePath() helper to prevent traversal (sigstore Release). As an immediate workaround without upgrading, set the environment variable SIGSTORE_NO_CACHE=true to disable disk caching in the legacy TUF client. The preferred long-term remediation is to migrate from the deprecated legacy TUF client to the new implementation at github.com/sigstore/sigstore-go/pkg/tuf. Additionally, ensure processes running the affected library operate with minimal filesystem permissions to limit the blast radius of any potential exploitation (Github Advisory).
The vulnerability was reported by security researcher 1seal and published by the sigstore maintainer Hayden-IO on January 22, 2026. The advisory notes that the legacy TUF client is already deprecated, and the maintainers recommend migration to the newer sigstore-go TUF implementation as the preferred long-term solution. Downstream distributions including SUSE, openSUSE, Fedora, Amazon Linux, and Red Hat have issued advisories and updates for affected packages (e.g., Cosign, vexctl, jfrog-cli) that bundle the vulnerable library (sigstore Advisory).
Fix availability across major Linux distributions and their releases.
sid
golang-github-sigstore-sigstore: 1.10.4-1
trixie
golang-github-sigstore-sigstore
devel
golang-github-sigstore-sigstore
noble
golang-github-sigstore-sigstore
noble (esm-apps)
golang-github-sigstore-sigstore
resolute
golang-github-sigstore-sigstore
resolute (esm-apps)
golang-github-sigstore-sigstore
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."