Skip to content
← archivevulnerability · 24 Sep 2026 · 18:19 UTC

GHSA-fgmf-7rf8-m6vf: ZITADEL: Actions V1 sandbox escape: host file read via require()

VULNCVE-2026-85057source · GTH
HIGHHigh-risk vulnerability — CVSS 8.7

last 60 dispatches · spectrum

### Summary A vulnerability in ZITADEL Actions V1 allows an organization Action author to read files from the ZITADEL host filesystem through the JavaScript `require()` module loader. On common self-hosted deployments this can be chained to steal bootstrap credentials (including the Login Client PAT) and escalate from a single-tenant organization owner to instance administrator. ### Impact ZITADEL Actions V1 run custom JavaScript inside the ZITADEL server process at OIDC, SAML, and login-flow trigger points. …

grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected