CVE-2026-32146
Gleam Gleam, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7 취약점
Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows arbitrary file system modification during dependency download. Dependency names from gleam.toml and manifest.toml are incorporated into filesystem paths without sufficient validation or confinement to the intended dependency directory, allowing attacker-controlled paths (via relative traversal such as ../ or absolute paths) to target filesystem locations outside that directory. When resolving git dependencies (e.g. via gleam deps download), the computed path is used for filesystem operations i...
- 대응 우선순위
- 점검
- CVSS
- 8.3
- EPSS
- 0.24% 백분위 15.2% · 2026.08.02 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.04.11