CVE-2019-19724: Sylabs Singularity

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to an information leak, and malicious redirection of operations performed against Sylabs cloud services.

Affected products

  • Sylabs Singularity: from 3.3.0, up to and including 3.5.1

Published 2019-12-18. Last modified 2026-06-17.