Intel

AIKIDO-2026-495532

nono is vulnerable to Improper Access Control

Improper Access ControlGHSA-222m-44fg-jx8g Published 6 days ago

50

Medium Risk

This Affects:

RUSTnono
0.0.1 - 0.77.0
Fixed in 0.78.0
Are you affected? Scan for Free

TL;DR

The @git:hooks-path and @git:files dynamic providers trust core.hooksPath, core.attributesFile, core.excludesFile, commit.template, and includeIf.path values from git config without checking whether the origin config file is writable by the sandboxed agent. An agent with a writable $HOME can point a global hooks path at a protected directory and receive a broker-granted read on that path. The origin config file itself stays readable because git needs it. The fix skips trusting those values when the origin file is covered by a Write capability.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use the @git:hooks-path or @git:files dynamic providers.

Background info

nono is vulnerable to Improper Access Control in versions 0.0.1 - 0.77.0.

How to fix this

Upgrade the nono library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform