<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Path Containment on SILO</title><link>https://silo.pgsty.com/tags/path-containment/</link><description>Recent content in Path Containment on SILO</description><generator>Hugo</generator><language>en</language><lastBuildDate>Wed, 05 Aug 2026 07:48:52 +0800</lastBuildDate><atom:link href="https://silo.pgsty.com/tags/path-containment/index.xml" rel="self" type="application/rss+xml"/><item><title>Internode Path Containment Audit: Paying Off What CVE-2026-42600 Left Owing</title><link>https://silo.pgsty.com/blog/security/internode-path-containment/</link><pubDate>Sun, 02 Aug 2026 00:00:00 +0000</pubDate><guid>https://silo.pgsty.com/blog/security/internode-path-containment/</guid><description>&lt;p&gt;&lt;strong&gt;Status:&lt;/strong&gt; Fixed on the local &lt;code&gt;pgsty/minio&lt;/code&gt; branch, &lt;strong&gt;unreleased and not disclosed&lt;/strong&gt; (no CVE/GHSA requested; the upstream repository is archived)
&lt;strong&gt;Affected scope:&lt;/strong&gt; Distributed erasure only; cluster-root / internode JWT required
&lt;strong&gt;Prerequisite reading:&lt;/strong&gt; &lt;a href="https://silo.pgsty.com/blog/security/cve-2026-42600/"&gt;CVE-2026-42600 · ReadMultiple&lt;/a&gt;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;This article contains complete exploitation vectors and measurements. Publishing it constitutes disclosure. Hold it until the fixed release ships.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;a href="https://silo.pgsty.com/blog/security/cve-2026-42600/"&gt;The previous entry&lt;/a&gt; closed with this sentence:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Deleting the endpoint proves only that &lt;code&gt;ReadMultiple&lt;/code&gt; no longer exists. It cannot be extrapolated into a completed containment audit of every internode body path.&lt;/p&gt;</description></item></channel></rss>