Filesystem Path Exposure in Linuxfabrik Monitoring Plugins and linuxfabrik-lib
CVE-2026-73974
What is CVE-2026-73974?
The linuxfabrik-lib, a library providing essential Python modules for various integrations, previously lacked proper path confinement when handling CSV arguments in the lib.lftest.test() function. This flaw allowed unauthorized access to filesystem paths, enabling attackers with control over the nagios or icinga account to exploit certain check plugins to reveal the contents of root-readable files. Affected versions prior to linuxfabrik-lib 6.1.0 and Linuxfabrik Monitoring Plugins 7.0.0 exposed sensitive information via various plugins by improperly filtering or allowing unauthorized read access. Recent updates have implemented fixes to confine read operations to specific plugin directories and mitigate these security risks.
Affected Version(s)
lib < 6.0.1
monitoring-plugins < 7.0.0
