{"success":true,"data":{"threats":[{"id":"fcbd75a9-c659-425b-bdd7-b38195d25402","slug":"cve-2026-89091","externalId":"CVE-2026-89091","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-89091 — A flaw was found in ansible-core.","description":"A flaw was found in ansible-core. When installing a collection with\n`ansible-galaxy collection install`, the archive extractor validates member\npaths using lexical path normalisation (os.path.abspath) instead of resolving\nsymbolic links (os.path.realpath), and it performs no containment check on\nsymlink-typed directory members before creating them. A crafted collection\ntarball can chain symlink directory entries so that a subsequent file member is\nwritten outside the intended destination directory. This allows an attacker who\ncan get a victim to install a malicious collection to overwrite arbitrary files\nwith the privileges of the user running ansible-galaxy, leading to code\nexecution on the control node. This is a bypass of the fix for CVE-2020-10691.","cveId":"CVE-2026-89091","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-59"],"tags":["nvd","status:received"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-89091","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2531646","type":"advisory","title":"secalert@redhat.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T22:17:35.777Z","addedAt":"2026-10-08T23:06:40.701Z","updatedAt":"2026-10-08T23:06:40.701Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89091","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-89091","note":"authoritative record"}]},{"id":"6006bd8e-0662-4ea9-966b-5f5c38592519","slug":"cve-2026-107716","externalId":"CVE-2026-107716","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107716 — Banks generates meaningful LLM prompts using a simple template language.","description":"Banks generates meaningful LLM prompts using a simple template language. Prior to 2.5.1, Banks DirectoryPromptRegistry does not reject symbolic links for index.json or discovered and existing .jinja prompt files. In an application where untrusted users can influence a prompt directory, DirectoryPromptRegistry._scan() and DirectoryPromptRegistry.get() can follow a link outside the registry root and disclose a file, while DirectoryPromptRegistry.set(), DirectoryPromptRegistry._save(), and DirectoryPromptRegistry._load() can read or overwrite an external link target. The issue requires attacker influence over the registry directory or its extracted contents. This issue is fixed in version 2.5.1.","cveId":"CVE-2026-107716","cvssScore":7.3,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-22","CWE-59"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/masci/banks/commit/23ed13e50b4e217693fa5f9c30943fac8a41582f","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/masci/banks/pull/79","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/masci/banks/releases/tag/v2.5.1","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/masci/banks/security/advisories/GHSA-556j-vv39-8rqv","type":"advisory","title":"security-advisories@github.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T22:17:27.323Z","addedAt":"2026-10-08T23:06:40.072Z","updatedAt":"2026-10-08T23:06:40.072Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107716","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107716","note":"authoritative record"}]},{"id":"b4beefc5-fe47-4c59-bd73-0c9decd67cc5","slug":"cve-2026-107707","externalId":"CVE-2026-107707","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107707 — Intego Antivirus for Windows through 3.0.0.1 contains a link following vulnerability in its optimization module that allows local unprivileged user…","description":"Intego Antivirus for Windows through 3.0.0.1 contains a link following vulnerability in its optimization module that allows local unprivileged users to delete arbitrary folders as SYSTEM. Attackers can replace a scanned duplicate file's directory with a junction to C:\\Config.msi and abuse Windows Installer rollback to execute code as SYSTEM.","cveId":"CVE-2026-107707","cvssScore":8.5,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-59"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://blog.quarkslab.com/milking-the-last-drop-of-intego-time-for-windows-to-get-its-lpe.html","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.intego.com/","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/intego-antivirus-through-3.0.0.1-local-privilege-escalation-via-optimization-module-junction","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:35.690Z","addedAt":"2026-10-08T21:05:53.368Z","updatedAt":"2026-10-08T23:06:39.362Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107707","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107707","note":"authoritative record"}]},{"id":"4b6ca1c2-6516-4bc7-aca2-8822b06b82ad","slug":"cve-2026-107608","externalId":"CVE-2026-107608","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107608 — Improper link resolution before file access in the asset bundling output handling in AWS aws-cdk-lib before 2.267.0 might allow a context-dependent…","description":"Improper link resolution before file access in the asset bundling output handling in AWS aws-cdk-lib before 2.267.0 might allow a context-dependent actor to cause files from the build host to be published as the deployed asset.\n\n\n\nTo remediate this issue, users should upgrade to version 2.267.0 or later.","cveId":"CVE-2026-107608","cvssScore":6.8,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-59"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://aws.amazon.com/security/security-bulletins/2026-131-aws/","type":"advisory","title":"ff89ba41-3aa1-4d27-914a-91399e9639e5"},{"url":"https://github.com/aws/aws-cdk/releases/tag/v2.267.0","type":"advisory","title":"ff89ba41-3aa1-4d27-914a-91399e9639e5"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:34.967Z","addedAt":"2026-10-08T21:05:53.252Z","updatedAt":"2026-10-08T23:06:39.312Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107608","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107608","note":"authoritative record"}]},{"id":"74e3da63-8c9e-49ab-8273-9e843b17a146","slug":"cve-2026-107578","externalId":"CVE-2026-107578","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107578 — Improper link resolution and external control of file paths in the administrative command-line operations of hMailServer.exe in Progressive Robot h…","description":"Improper link resolution and external control of file paths in the administrative command-line operations of hMailServer.exe in Progressive Robot hMailServer 6.3.4 and 6.3.5 allow a local attacker who already runs code as the low-privilege service account to escalate privilege. On Windows, operations run with administrator rights by the installer, DBSetup, the Control Panel or an administrator wrote log entries and crash records into the log folder, created, deleted and changed the permissions of the self-signed certificate and private key in the data folder, and rewrote message files in the data folder, all by path in folders the service account (NT SERVICE\\hMailServer, the default for new installations since 6.3.4) can modify, following junctions and mount points; and the store-maintenance operations reached files by names taken from the database, which the service account can write, including names outside the data folder. On Linux, the store-maintenance and object-storage operations run as root followed symbolic links the service account (the packaged hmailserver user, which owns the data folder) planted in it, so a root-run operation read, wrote or removed the link's target as root. A local attacker controlling the service account can thereby gain the administrator's (Windows) or root's (Linux) privileges when such an operation is run.","cveId":"CVE-2026-107578","cvssScore":6.7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-59"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.6","type":"advisory","title":"cve@gitlab.com"},{"url":"https://gitlab.com/hmailserver/hmailserver/-/work_items/71","type":"advisory","title":"cve@gitlab.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T12:17:15.787Z","addedAt":"2026-10-08T12:39:41.365Z","updatedAt":"2026-10-08T23:06:37.707Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107578","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107578","note":"authoritative record"}]},{"id":"eb6a22cc-3a97-45db-b0c9-025041b174c7","slug":"cve-2026-106508","externalId":"CVE-2026-106508","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106508 — Backstage is an open framework for building developer portals.","description":"Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by potential file exposure through local techdocs publisher. When using the local TechDocs publisher (techdocs.publisher.type: 'local'), it was possible for the documentation serving endpoint to follow filesystem references outside the intended documentation tree, potentially exposing host files to authenticated users. This is mitigated by the fact that exploration requires preconditions that do not arise through normal MkDocs operation. Cloud-based publishers (S3, GCS, Azure Blob Storage) are not affected. This issue is fixed in version 1.15.4.","cveId":"CVE-2026-106508","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","severity":"medium","vendor":"npm","product":"@backstage/plugin-techdocs-node","affectedVersions":["pkg:npm/%40backstage/plugin-techdocs-node < 1.15.4"],"cwes":["CWE-22","CWE-59"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-cm77-ch27-6w6v","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/backstage/backstage/commit/6aecb26f337ffec1d4e67ce903cf1e39b6082ec4","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.54.6","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/security/advisories/GHSA-cm77-ch27-6w6v","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-cm77-ch27-6w6v","type":"advisory","title":"OSV GHSA-cm77-ch27-6w6v"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106508","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/backstage/backstage","type":"vendor","title":"OSV package"}],"epssScore":0.00283,"epssPercentile":0.19039,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T22:17:06.310Z","addedAt":"2026-10-06T22:39:33.257Z","updatedAt":"2026-10-07T18:42:44.668Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106508","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106508","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-CM77-CH27-6W6V"}]},{"id":"7e52e0d6-8641-4a5d-8c35-a09a50ab5266","slug":"cve-2026-106507","externalId":"CVE-2026-106507","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106507 — Backstage is an open framework for building developer portals.","description":"Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by techdocs arbitrary file read via mkdocs snippets. Unsafe path resolution in TechDocs source tree handling allows an authenticated user who can register documentation sources to include content from outside the intended documentation boundary. Depending on deployment, this may expose files readable by the build process. This issue is fixed in version 1.15.4.","cveId":"CVE-2026-106507","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-59","CWE-61"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/backstage/backstage/commit/911ca36f10e654c5517da029129230fc05a4f580","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.54.6","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/backstage/backstage/security/advisories/GHSA-vmqh-7cj9-mvcj","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00283,"epssPercentile":0.19039,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T22:17:06.153Z","addedAt":"2026-10-06T22:39:33.249Z","updatedAt":"2026-10-07T16:39:31.372Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106507","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106507","note":"authoritative record"}]},{"id":"04492aec-2a6c-49e6-9586-fe65ffc31997","slug":"cve-2026-106500","externalId":"CVE-2026-106500","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106500 — Backstage is an open framework for building developer portals.","description":"Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper task state validation in scaffolder backend. An authenticated user with permission to create and access Scaffolder tasks may, under specific timing and deployment conditions, affect files accessible to the Backstage backend. If backend application files are writable, the confidentiality, integrity, and availability of the backend may be compromised. This issue is fixed in versions 3.3.1, 3.4.1, 4.0.3 and 4.1.0.","cveId":"CVE-2026-106500","cvssScore":8.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","severity":"high","vendor":"npm","product":"@backstage/plugin-scaffolder-backend","affectedVersions":["pkg:npm/%40backstage/plugin-scaffolder-backend < 4.1.0"],"cwes":["CWE-59","CWE-362"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-xvgh-hmx8-9xxf","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/backstage/backstage/commit/0d24f1b8701f3dde6cd597f81997c1ea873a43ae","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/commit/56be299dd3ef6706e13e76ea2f8a9b0dd0b6413d","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/commit/9e86c95a1a3ddfd54db03731cd8678aa63495175","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.49.6","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.50.5","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.54.6","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/security/advisories/GHSA-xvgh-hmx8-9xxf","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-xvgh-hmx8-9xxf","type":"advisory","title":"OSV GHSA-xvgh-hmx8-9xxf"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106500","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/backstage/backstage","type":"vendor","title":"OSV package"}],"epssScore":0.00328,"epssPercentile":0.23914,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T22:17:05.060Z","addedAt":"2026-10-06T22:39:33.197Z","updatedAt":"2026-10-07T18:42:42.572Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106500","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106500","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-XVGH-HMX8-9XXF"}]},{"id":"00ef4ea5-f221-454c-9752-54faa108b8b9","slug":"cve-2026-106486","externalId":"CVE-2026-106486","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106486 — Backstage is an open framework for building developer portals.","description":"Backstage is an open framework for building developer portals. Prior to 0.3.10 in @backstage/plugin-scaffolder-backend-module-bitbucket-cloud and 0.2.25 in @backstage/plugin-scaffolder-backend-module-bitbucket-server, the Bitbucket pull-request Scaffolder actions did not sufficiently validate filesystem paths. An authenticated user who can execute an eligible template and influence an allowed Bitbucket repository could affect paths outside the expected working area, potentially compromising backend confidentiality, integrity, or availability. This issue is fixed in @backstage/plugin-scaffolder-backend-module-bitbucket-cloud 0.3.10 and @backstage/plugin-scaffolder-backend-module-bitbucket-server 0.2.25.","cveId":"CVE-2026-106486","cvssScore":8.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","severity":"high","vendor":"npm","product":"@backstage/plugin-scaffolder-backend-module-bitbucket-cloud","affectedVersions":["pkg:npm/%40backstage/plugin-scaffolder-backend-module-bitbucket-cloud < 0.3.10","pkg:npm/%40backstage/plugin-scaffolder-backend-module-bitbucket-server < 0.2.25"],"cwes":["CWE-22","CWE-59"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-g8rx-f7m5-7794","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/backstage/backstage/commit/818528e112c36167d76187e9e63fb518399c4dd2","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.54.6","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/security/advisories/GHSA-g8rx-f7m5-7794","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-g8rx-f7m5-7794","type":"advisory","title":"OSV GHSA-g8rx-f7m5-7794"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106486","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/backstage/backstage","type":"vendor","title":"OSV package"}],"epssScore":0.00325,"epssPercentile":0.23578,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T21:17:17.323Z","addedAt":"2026-10-06T22:39:32.987Z","updatedAt":"2026-10-07T18:42:42.895Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106486","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106486","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-G8RX-F7M5-7794"}]},{"id":"154124cb-06b0-4b60-8a9f-35309450e2d1","slug":"cve-2026-76061","externalId":"CVE-2026-76061","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-76061 — A flaw was found in CRI-O's `bind_mount_prefix` handling.","description":"A flaw was found in CRI-O's `bind_mount_prefix` handling. When configured with a non-empty `bind_mount_prefix`, a malicious container or local attacker could use a Container Runtime Interface (CRI) hostPath containing an intermediate absolute symlink. This could cause the bind mount source to resolve outside the intended prefixed root, potentially leading to unauthorized access to files or privilege escalation on the host system.","cveId":"CVE-2026-76061","cvssScore":5.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-59"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-76061","type":"advisory","title":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2520330","type":"advisory","title":"secalert@redhat.com"},{"url":"https://github.com/cri-o/cri-o/commit/01f90366dc8c8db0df32b4aae7fd067c1eddbb70","type":"advisory","title":"secalert@redhat.com"},{"url":"https://github.com/cri-o/cri-o/commit/6d08a9a60ecfabdb3cbea0c8d698e31f1f01cb40","type":"advisory","title":"secalert@redhat.com"},{"url":"https://github.com/cri-o/cri-o/commit/d6f58973acfcae93ecc039e0297fbe5f2548b46b","type":"advisory","title":"secalert@redhat.com"}],"epssScore":0.0023,"epssPercentile":0.12663,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T20:17:29.123Z","addedAt":"2026-10-06T20:39:33.157Z","updatedAt":"2026-10-07T16:39:30.855Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76061","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-76061","note":"authoritative record"}]},{"id":"f80f0281-2f05-4e43-98c1-8c47e85875d6","slug":"ghsa-8w8g-wq8h-fq33","externalId":"GHSA-8w8g-wq8h-fq33","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"Dulwich: Symlink write-through in checkout(paths=[]) via raw os.open bypasses all symlink protections","description":"## Summary\n\nDulwich's `porcelain.checkout(paths=[...])` code path writes files using raw `os.open(file_path, O_WRONLY|O_CREAT|O_TRUNC, mode)` followed by `f.write(obj.data)`. This code path does NOT call `build_file_from_blob()` at all, completely bypassing any symlink protections (including the unreleased d09f8af fix). `os.open` without `O_NOFOLLOW` follows symlinks at both the target file and intermediate directories, allowing arbitrary file writes.\n\n## Root Cause\n\nAt `dulwich/porcelain/__init__.py:5661-5675`, the `checkout(paths=[...])` implementation:\n\n```python\nfile_path = _checked_worktree_path(r, path)\nos.makedirs(os.path.dirname(file_path), exist_ok=True)\nflags = os.O_WRONLY | os.O_CREAT | os.O_TRUNC\nwith os.fdopen(os.open(file_path, flags, mode), \"wb\") as f:\n    f.write(obj.data)\n```\n\n`_checked_worktree_path()` (line 601-631) only performs name validation — checking that the path doesn't start with `/` or `\\\\` and that components pass `INVALID_DOTNAMES` checks. It performs zero filesystem symlink detection.\n\n## Impact\n\nAn attacker can craft a malicious repository that, when a victim clones it and runs `checkout(paths=[...])`, writes attacker-controlled content (with attacker-controlled permissions) to any filesystem location accessible to the user. Writing to `.git/hooks/post-checkout` achieves RCE on the next git checkout.\n\n## Attack Scenario\n\n1. Attacker creates a repository where HEAD has `trigger` as a symlink (mode 120000, content `../../.git/hooks/post-checkout`), and tag `v1.0` has `trigger` as an executable file (mode 100755, content `#!/bin/sh\\nmalicious_payload`)\n2. Victim clones the repository — worktree has `trigger` → `../../.git/hooks/post-checkout` (a symlink)\n3. Victim runs `porcelain.checkout(repo, target=\"v1.0\", paths=[\"trigger\"])` to restore a specific file from a tag\n4. `_checked_worktree_path(r, \"trigger\")` passes — name validation only, no symlink check\n5. `os.open(\"trigger\", O_WRONLY|O_CREAT|O_TRUNC, 0o755)` follows the symlink → opens `.git/hooks/post-checkout` for writing\n6. `f.write(obj.data)` writes the malicious payload to the hook\n7. Next checkout operation triggers the hook → RCE\n\n## Suggested Fix\n\nReplace the raw `os.open` path with a call to `build_file_from_blob` (once that function is hardened against intermediate symlinks), or add explicit symlink detection: resolve the path with `os.path.realpath()` and verify it stays within the worktree root before opening.\n\nReported by **zx (Jace)**","cveId":null,"cvssScore":null,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","severity":"high","vendor":"PyPI","product":"dulwich","affectedVersions":["pkg:pypi/dulwich >= 0.24.0, < 1.2.8"],"cwes":["CWE-59","CWE-61"],"tags":["osv","osv:ghsa-8w8g-wq8h-fq33","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-8w8g-wq8h-fq33","type":"advisory","title":"OSV GHSA-8w8g-wq8h-fq33"},{"url":"https://github.com/jelmer/dulwich/security/advisories/GHSA-8w8g-wq8h-fq33","type":"other","title":"OSV web"},{"url":"https://github.com/jelmer/dulwich/commit/9389fcb5cb9113adfc7f207d8be86a56904db3e8","type":"other","title":"OSV web"},{"url":"https://github.com/jelmer/dulwich","type":"vendor","title":"OSV package"},{"url":"https://github.com/jelmer/dulwich/releases/tag/dulwich-1.2.8","type":"other","title":"OSV web"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T18:53:35.000Z","addedAt":"2026-10-02T19:54:22.609Z","updatedAt":"2026-10-02T19:54:22.609Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-8w8g-wq8h-fq33"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-8w8g-wq8h-fq33"}]},{"id":"accd293a-945f-4ad9-8d5b-a64761bb1d59","slug":"ghsa-5fqc-mrg8-w798","externalId":"GHSA-5fqc-mrg8-w798","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"Dulwich: Symlink directory traversal in filter-branch index_filter via cross-commit state persistence","description":"## Summary\n\nDulwich's `filter_branch.py` `CommitFilter._apply_index_filter()` is vulnerable to symlink directory traversal. When processing commit history, materialized tree entries (including symlinks) persist in the working directory between commits, allowing a symlink from an ancestor commit to redirect file writes from a descendant commit to arbitrary filesystem locations.\n\n## Root Cause\n\n`_apply_index_filter()` at `dulwich/filter_branch.py:212` calls `build_index_from_tree(\".\", tmp_index_path, ...)` which materializes all tree entries to the current working directory. The `finally` block (line 229-230) only cleans up the temporary index file (`os.unlink(tmp_index_path)`) — NOT the filesystem files written to CWD. When `process_commit()` processes parents recursively first (line 260), files materialized from ancestor commits persist and affect processing of descendant commits.\n\nOn dulwich 1.2.7, `build_file_from_blob()` has no symlink protection, and `validate_path_element` only validates name patterns, not filesystem state.\n\n## Impact\n\nAn attacker can craft a malicious repository where running `filter_branch` with an index filter writes attacker-controlled content to arbitrary filesystem locations via symlink traversal. This achieves RCE if the write targets `.git/hooks/`.\n\n## Attack Scenario\n\n1. Attacker creates a repository where commit history (linearized) has:\n   - Ancestor commit: tree entry `evil` (mode 120000, symlink → `/target_dir`)\n   - Descendant commit: tree entry `evil/payload` (mode 100644, attacker content)\n2. Victim clones repository and runs `filter_branch` with an index filter\n3. `process_commit()` processes ancestor first → materializes `evil` as symlink to `/target_dir` in CWD\n4. CWD is NOT cleaned between commits\n5. Processing descendant: `os.path.exists(\"./evil\")` → True (symlink exists). `build_file_from_blob(blob, mode, \"./evil/payload\")` → `open(\"./evil/payload\", \"wb\")` follows intermediate symlink → writes to `/target_dir/payload`\n\n## Suggested Fix\n\nClean the CWD between commit iterations in `_apply_index_filter()`, or verify that no intermediate path components are symlinks before writing files.\n\nReported by **zx (Jace)**","cveId":null,"cvssScore":null,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","severity":"high","vendor":"PyPI","product":"dulwich","affectedVersions":["pkg:pypi/dulwich >= 0.23.1, < 1.2.8"],"cwes":["CWE-22","CWE-59"],"tags":["osv","osv:ghsa-5fqc-mrg8-w798","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-5fqc-mrg8-w798","type":"advisory","title":"OSV GHSA-5fqc-mrg8-w798"},{"url":"https://github.com/jelmer/dulwich/security/advisories/GHSA-5fqc-mrg8-w798","type":"other","title":"OSV web"},{"url":"https://github.com/jelmer/dulwich/commit/9571ac60b851fce228dae7ededb380c6ce9b3fb8","type":"other","title":"OSV web"},{"url":"https://github.com/jelmer/dulwich","type":"vendor","title":"OSV package"},{"url":"https://github.com/jelmer/dulwich/releases/tag/dulwich-1.2.8","type":"other","title":"OSV web"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T18:53:05.000Z","addedAt":"2026-10-02T19:54:22.618Z","updatedAt":"2026-10-02T19:54:22.618Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-5fqc-mrg8-w798"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-5fqc-mrg8-w798"}]},{"id":"1a30ac86-f76f-452f-a8c4-e408616418e9","slug":"ghsa-cm62-gvxx-vmxx","externalId":"GHSA-cm62-gvxx-vmxx","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"Dulwich: Symlink directory traversal in stash pop allows arbitrary file write via intermediate directory symlinks","description":"## Summary\n\nDulwich's `stash.py:pop()` function is vulnerable to symlink directory traversal, allowing an attacker to write arbitrary files outside the repository worktree when a victim pops a stash in a malicious repository.\n\n## Root Cause\n\nThe `pop()` function at `dulwich/stash.py:236` uses `os.path.exists(parent_dir)` to check if a parent directory exists before writing stashed files. `os.path.exists()` follows symlinks, so when an intermediate directory in the path is a symlink pointing outside the worktree (e.g., `link → ../../.git/hooks`), the check passes and subsequent file writes resolve through the symlink.\n\nThe `validate_path()` function (line 228) only validates path component names against `INVALID_DOTNAMES` — it performs zero filesystem symlink detection. On dulwich 1.2.7 (latest release), `build_file_from_blob()` has no symlink protection whatsoever.\n\n## Impact\n\nAn attacker can craft a malicious repository that, when a victim clones it and performs a stash pop operation, writes attacker-controlled content to arbitrary filesystem locations. Writing to `.git/hooks/post-checkout` achieves Remote Code Execution on the victim's machine on the next git checkout operation.\n\n## Attack Scenario\n\n1. Attacker creates a repository with branch `main` containing `link` (symlink → `../../.git/hooks`) and branch `feature` containing `link/post-checkout` (executable payload)\n2. Victim clones the repository (landing on `main` — symlink `link` exists in worktree)\n3. Victim checks out `feature`, makes changes, runs `stash.push()`\n4. Victim checks out `main` (restoring the `link` symlink)\n5. Victim runs `stash.pop(0)` — stash contains `link/post-checkout`\n6. `os.path.exists(\"link\")` returns True (symlink to existing directory), `os.makedirs` skipped\n7. `build_file_from_blob(blob, mode, \"link/post-checkout\")` → `open(\"link/post-checkout\", \"wb\")` follows the intermediate symlink → payload written to `.git/hooks/post-checkout`\n8. Next checkout operation triggers the hook → RCE\n\n## Suggested Fix\n\nBefore writing any file, verify that no component of the target path resolves through a symlink outside the worktree. Use `os.path.realpath(parent_dir)` and confirm it stays within the repository root. Alternatively, use `os.open()` with `O_NOFOLLOW` on each path component.\n\nReported by **zx (Jace)**","cveId":null,"cvssScore":null,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","severity":"high","vendor":"PyPI","product":"dulwich","affectedVersions":["pkg:pypi/dulwich >= 0.22.5, < 1.2.8"],"cwes":["CWE-22","CWE-59"],"tags":["osv","osv:ghsa-cm62-gvxx-vmxx","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-cm62-gvxx-vmxx","type":"advisory","title":"OSV GHSA-cm62-gvxx-vmxx"},{"url":"https://github.com/jelmer/dulwich/security/advisories/GHSA-cm62-gvxx-vmxx","type":"other","title":"OSV web"},{"url":"https://github.com/jelmer/dulwich/commit/40a542cb02f9ac39a9eeac1193472903098698f9","type":"other","title":"OSV web"},{"url":"https://github.com/jelmer/dulwich","type":"vendor","title":"OSV package"},{"url":"https://github.com/jelmer/dulwich/releases/tag/dulwich-1.2.8","type":"other","title":"OSV web"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-02T18:52:53.000Z","addedAt":"2026-10-02T19:54:22.594Z","updatedAt":"2026-10-02T19:54:22.594Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-cm62-gvxx-vmxx"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-cm62-gvxx-vmxx"}]},{"id":"dde7a63f-3bd3-48fc-9576-bb1d238f06ee","slug":"cve-2026-94620","externalId":"CVE-2026-94620","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-94620 — Classroom 50 is a free and open-source tool for managing and grading programming assignments via GitHub.","description":"Classroom 50 is a free and open-source tool for managing and grading programming assignments via GitHub. Prior to version 1.11.0, `gh teacher download` clones each student's assignment repository and then writes autograde artifacts (`result.json` and `results.json`) into the just-cloned working tree. The write followed symlinks, so a student who committed `result.json` or `results.json` as a **symlink** (materialized verbatim by `git clone`) could redirect the teacher's write to an arbitrary path — e.g. `~/.zshrc`, `~/.ssh/authorized_keys`, a cron file, or an in-clone `.git/hooks/*` file that git subsequently executes. The written bytes are attacker-controlled (the student's uploaded release asset for `result.json`; student-chosen submit-tag names for `results.json`). This is an arbitrary file write leading to code execution as the teacher, whose `gh` token carries `admin:org`, `repo`, and `workflow` across the entire classroom organization. Version 1.11.0 contains a patch. Some workarounds are available. Avoid running `gh teacher download` against untrusted student repositories, or run it inside a disposable sandbox / container with no access to sensitive host files or credentials. Inspect cloned trees for symlinked, hardlinked, or special (`result.json`/`results.json`) entries before allowing the artifact-refresh step to run.","cveId":"CVE-2026-94620","cvssScore":9.4,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-22","CWE-59"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/foundation50/classroom50/commit/79112f33932d1b5c398a8801d97a8813d52d55ce","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/foundation50/classroom50/security/advisories/GHSA-qx2g-vpwq-466c","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00415,"epssPercentile":0.33804,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-01T16:18:08.550Z","addedAt":"2026-10-01T17:50:42.762Z","updatedAt":"2026-10-02T19:50:40.148Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94620","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-94620","note":"authoritative record"}]},{"id":"bc8af06e-0fef-4d3a-94eb-d3ad1aed1909","slug":"cve-2026-103263","externalId":"CVE-2026-103263","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-103263 — Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confir…","description":"Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user.","cveId":"CVE-2026-103263","cvssScore":8.2,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"PyPI","product":"tornado","affectedVersions":["pkg:pypi/tornado < 6.5.9"],"cwes":["CWE-59"],"tags":["nvd","status:deferred","osv","osv:ghsa-c2m8-h5v5-343r","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/tornadoweb/tornado/commit/437ab5f76565403b3403438d2e555d11f8128d32","type":"other","title":"OSV web"},{"url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r","type":"other","title":"OSV web"},{"url":"https://www.vulncheck.com/advisories/tornado-before-6.5.9-staticfilehandler-path-traversal-via-symlink","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://osv.dev/vulnerability/GHSA-c2m8-h5v5-343r","type":"advisory","title":"OSV GHSA-c2m8-h5v5-343r"},{"url":"https://github.com/tornadoweb/tornado/pull/3719","type":"other","title":"OSV web"},{"url":"https://github.com/tornadoweb/tornado/commit/f9f50b8bab265a2abf9f2415a3d2da6264a5450b","type":"other","title":"OSV web"},{"url":"https://github.com/tornadoweb/tornado","type":"vendor","title":"OSV package"},{"url":"https://github.com/tornadoweb/tornado/releases/tag/v6.5.9","type":"other","title":"OSV web"}],"epssScore":0.00522,"epssPercentile":0.42465,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-01T11:17:21.233Z","addedAt":"2026-10-01T11:50:39.902Z","updatedAt":"2026-10-02T07:54:22.778Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103263","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-103263","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-C2M8-H5V5-343R"}]},{"id":"d1a1d19d-4f32-4573-b125-575157bf7ca2","slug":"ghsa-c2m8-h5v5-343r","externalId":"GHSA-c2m8-h5v5-343r","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"Tornado: StaticFileHandler follows symlinks outside static root (path traversal)","description":"### Summary\nStaticFileHandler allows an unauthenticated attacker to read arbitrary files from the server's filesystem by requesting a path that resolves to a symbolic link placed inside the static root directory. Any application that serves user-uploadable content, or whose static directory is populated by a build/deploy pipeline that creates symlinks (e.g. npm link, webpack, Docker volume mounts, CDN sync tools), is affected. An attacker who can trigger the creation of a symlink pointing outside the static root—or exploit one that already exists—can retrieve sensitive files such as /etc/passwd, private keys, configuration files, or application secrets.\n\n\n\n### Details\nThe vulnerability is in tornado.web.StaticFileHandler, specifically in the interaction between two methods in [tornado/web.py](vscode-webview://1grdaaa6v64itrol06qu70pq3d1b9h9im5c3npvvc9snaprc1q9f/tornado/web.py):\n- [get_absolute_path](https://github.com/tornadoweb/tornado/blob/0ca3c5f8279d402b245718d16522bc18a8f5d958/tornado/web.py#L2932) uses `os.path.abspath()` to resolve the requested path:\n- [validate_absolute_path](https://github.com/tornadoweb/tornado/blob/0ca3c5f8279d402b245718d16522bc18a8f5d958/tornado/web.py#L2935) uses the same `os.path.abspath()` on the root, then performs a string prefix check:\n\n`os.path.abspath()` normalises . and .. segments but does not resolve symbolic links. As a result, a path like `/var/www/static/link` passes the `startswith(\"/var/www/static/\")` check regardless of where `link` actually points.\n\nImmediately after, `os.path.exists()` and `os.path.isfile()`  **do follow symlinks**, so the file they ultimately open is the symlink's target. The fix would be to replace os.path.abspath() with os.path.realpath() in both methods, so the resolved real path of the symlink target is validated against the root, not just its string representation inside the static directory.\n\n### PoC\n_Complete instructions, including specific configuration details, to reproduce the vulnerability._\nPrerequisites: Python 3.x, Tornado installed.\n1. Create the environment\n```\nmkdir -p /tmp/static\necho \"DB_PASSWORD=s3cr3t\" > /tmp/secret.conf   \nln -s /tmp/secret.conf /tmp/static/config.conf \n```\n2. Minimal vulnerable server (server.py):\n```\nimport tornado.web, tornado.ioloop\n\napp = tornado.web.Application([\n    (r\"/static/(.*)\", tornado.web.StaticFileHandler, {\"path\": \"/tmp/static\"}),\n])\napp.listen(8888)\ntornado.ioloop.IOLoop.current().start()\n```\n3. Exploit:\n`curl http://localhost:8888/static/config.conf`\n\n### Impact\nAny application using StaticFileHandler is potentially affected if:\n- the static directory contains symlinks pointing outside it (common with build tooling), or\n- the application allows file uploads into the static directory without stripping symlinks.\n\nAn unauthenticated remote attacker can read any file readable by the process user: application secrets, private TLS keys, database credentials, /etc/shadow, SSH keys, or source code (depending on the process's filesystem permissions).","cveId":null,"cvssScore":null,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","severity":"high","vendor":"PyPI","product":"tornado","affectedVersions":["pkg:pypi/tornado < 6.5.9"],"cwes":["CWE-59"],"tags":["osv","osv:ghsa-c2m8-h5v5-343r","ecosystem:pypi"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-c2m8-h5v5-343r","type":"advisory","title":"OSV GHSA-c2m8-h5v5-343r"},{"url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r","type":"other","title":"OSV web"},{"url":"https://github.com/tornadoweb/tornado/pull/3719","type":"other","title":"OSV web"},{"url":"https://github.com/tornadoweb/tornado/commit/437ab5f76565403b3403438d2e555d11f8128d32","type":"other","title":"OSV web"},{"url":"https://github.com/tornadoweb/tornado/commit/f9f50b8bab265a2abf9f2415a3d2da6264a5450b","type":"other","title":"OSV web"},{"url":"https://github.com/tornadoweb/tornado","type":"vendor","title":"OSV package"},{"url":"https://github.com/tornadoweb/tornado/releases/tag/v6.5.9","type":"other","title":"OSV web"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T23:48:55.000Z","addedAt":"2026-10-01T01:54:19.930Z","updatedAt":"2026-10-01T01:54:19.930Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-c2m8-h5v5-343r"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-c2m8-h5v5-343r"}]},{"id":"59efed6c-bae8-429d-8313-1f00a2d1b88e","slug":"cve-2026-102118","externalId":"CVE-2026-102118","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102118 — A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an existing shell under a low-privileged service accoun…","description":"A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an existing shell under a low-privileged service account to escalate to root privileges on the appliance.","cveId":"CVE-2026-102118","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"accellion","product":"kiteworks","affectedVersions":["< 9.5.0"],"cwes":["CWE-59","CWE-250"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/kiteworks/security-advisories/security/advisories/GHSA-8pmh-222g-6j48","type":"vendor","title":"Vendor Advisory"},{"url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json","type":"advisory","title":"Broken Link"}],"epssScore":0.00397,"epssPercentile":0.31771,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T21:16:59.707Z","addedAt":"2026-09-30T21:50:45.143Z","updatedAt":"2026-10-07T14:39:32.377Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102118","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102118","note":"authoritative record"}]},{"id":"a95d9118-df7e-42d6-9361-f159342cb5c6","slug":"cve-2026-102113","externalId":"CVE-2026-102113","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-102113 — A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend servic…","description":"A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance to escalate to root. A privileged routine did not safely handle a filesystem path that the lower-privileged account could influence, allowing the attacker to cause a root-owned operation to run arbitrary commands with the highest privileges. Exploitation requires existing local access to that service account.","cveId":"CVE-2026-102113","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"accellion","product":"kiteworks","affectedVersions":["< 9.5.0"],"cwes":["CWE-59","CWE-269"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/kiteworks/security-advisories/security/advisories/GHSA-gwj7-wxrr-28v5","type":"vendor","title":"Vendor Advisory"},{"url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/VA/white/2026/va-26-274-01.json","type":"advisory","title":"Broken Link"}],"epssScore":0.00389,"epssPercentile":0.30933,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T21:16:58.427Z","addedAt":"2026-09-30T21:50:45.098Z","updatedAt":"2026-10-07T14:39:32.345Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102113","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-102113","note":"authoritative record"}]},{"id":"049b374f-fdb8-4dc1-86d5-22e26efa1a50","slug":"cve-2026-10739","externalId":"CVE-2026-10739","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-10739 — Cato Networks SDP Client for Windows before 6.12.6 allows a local user to delete arbitrary files with SYSTEM privileges via improper validation of …","description":"Cato Networks SDP Client for Windows before 6.12.6 allows a local user to delete arbitrary files with SYSTEM privileges via improper validation of a client-supplied SID over a local IPC named pipe.","cveId":"CVE-2026-10739","cvssScore":8.5,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-23","CWE-59","CWE-73"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://knowledge.catonetworks.com/docs/cve-2026-10726-cve-2026-10739-impacts-windows-client-versions-lower-than-6126","type":"advisory","title":"2505284f-8ffb-486c-bf60-e19c1097a90b"}],"epssScore":0.0012,"epssPercentile":0.01678,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T12:17:12.963Z","addedAt":"2026-09-30T13:50:40.123Z","updatedAt":"2026-09-30T19:50:43.018Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-10739","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-10739","note":"authoritative record"}]},{"id":"15459e9a-8677-43e1-a400-61c0e451cbc7","slug":"cve-2026-81310","externalId":"CVE-2026-81310","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-81310 — Image Scanner Driver for Linux contains a link following vulnerability.","description":"Image Scanner Driver for Linux contains a link following vulnerability. An attacker who can log in to a Linux system where the product is installed may overwrite arbitrary files by using a special method in advance.","cveId":"CVE-2026-81310","cvssScore":5.2,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-59"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://jvn.jp/en/vu/JVNVU96968110/","type":"advisory","title":"vultures@jpcert.or.jp"},{"url":"https://www.pfu.ricoh.com/global/products_security/vul2026000001e.html","type":"advisory","title":"vultures@jpcert.or.jp"}],"epssScore":0.00119,"epssPercentile":0.01618,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-30T02:16:57.747Z","addedAt":"2026-09-30T03:50:38.968Z","updatedAt":"2026-09-30T17:50:46.735Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81310","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-81310","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":343,"totalPages":18,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:15:35.606Z","durationMs":99,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-59"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}