CVE-2026-32146
Gleam Gleam, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7
Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows arbitrary file system modification during dependency download. Dependency names from gleam.toml and manifest.toml are incorporated into filesystem paths without sufficient validation or confinement to the intended dependency directory, allowing attacker-controlled paths (via relative traversal such as ../ or absolute paths) to target filesystem locations outside that directory. When resolving git dependencies (e.g. via gleam deps download), the computed path is used for filesystem operations i...
- CVSS
- 8.3
- EPSS
- 0.24% 15.1% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.11