The Dark Side of Flexibility: Detecting Risky Permission Chaining Attacks in Serverless Applications
Xunqi Liu, Nanzi Yang, Chang Li, Jinku Li, Jianfeng Ma, Kangjie Lu
Abstract
—Modern serverless platforms enable rapid application evolution by decoupling infrastructure from function-level development. However, this flexibility introduces a fundamental mismatch between the decentralized, function-level privilege configurations of serverless applications and the centralized cloud access control systems. We observe that this mismatch commonly incurs risky permissions of functions in serverless applications, and an attacker can chain multiple risky-permissioned functions to escalate privileges, take over the account, and even move laterally to compromise other accounts. We term such an attack a risky permission chaining attack . In this work, we propose an automated reasoning system that can detect risky permissions that are exploitable for chaining attacks. First, we root in attacker-centric modality abstraction, which explicitly captures how independent permissions from different functions and accounts can be merged into real attack chains. Based on this abstraction, we build a modality-guided detection tool that uncovers exploitable privilege chains in real-world serverless applications. We evaluate our approach across two major cloud platforms — AWS and Alibaba Cloud — by analyzing serverless applications sourced from their official, production-grade application repositories. As a result, our analysis uncovers 28 vulnerable applications, including five confirmed CVEs, six responsible vulnerability acknowledgments, and one security bounty. These findings underscore that the risky permission chaining attack is not only a theoretical risk but also a structural and exploitable threat already present in commercial serverless deployments, rooted in the fundamental mismatch between decentralized serverless applications and centralized access control models.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 58728dc9-2f27-469b-abdd-2592990b5e7aBuilds on11
- Valve: Securing Function Workflows on Serverless Computing PlatformsPubali Datta, Prabuddha Kumar, Tristan Morris, Michael Grace et al.WWW 2020 · 79 citations
- CLARION: Sound and Clear Provenance Tracking for Microservice DeploymentsXutong Chen, Hassaan Irshad, Yan Chen, Ashish Gehani et al.USENIX Security 2021 · 38 citations
- Automating serverless deployments for DevOps organizationsDaniel Sokolowski, Pascal Weisenburger, Guido SalvaneschiFSE 2021 · 28 citations
- Warmonger: Inflicting Denial-of-Service via Serverless Functions in the CloudJunjie Xiong, Mingkui Wei, Zhuo Lu, Yao LiuCCS 2021 · 21 citations
- Gringotts: Fast and Accurate Internal Denial-of-Wallet Detection for Serverless ComputingJunxian Shen, Han Zhang, Yantao Geng, Jiawei Li et al.CCS 2022 · 19 citations
Related papers
- ALPS: Automated Least-Privilege Enforcement for Securing Serverless FunctionsChanghee Shin, Bom Kim, Seungsoo LeeINFOCOM 2026 · 1 citation
- GRASP: Hardening Serverless Applications through Graph Reachability Analysis of Security PoliciesIsaac Polinsky, Pubali Datta, Adam Bates, William EnckWWW 2024 · 15 citations
- Bit of a Close Talker: A Practical Guide to Serverless Cloud Co-Location AttacksWei Shao, Najmeh Nazari, Behnam Omidi, Setareh Rafatirad et al.NDSS 2026 · 2 citations
- ChainReactor: Automated Privilege Escalation Chain Discovery via AI PlanningGiulio De Pasquale, Ilya Grishchenko, Riccardo Iesari, Gabriel Pizarro et al.USENIX Security 2024 · 15 citations
- CloudFlow: Identifying Security-sensitive Data Flows in Serverless ApplicationsGiuseppe Raffa, Jorge Blasco, Daniel O'Keeffe, Santanu Kumar DashUSENIX Security 2025
