Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows...

zetlyn/cve-ghsa vulnerability ghsa GHSA-4cjq-6jh9-w2f5 cve CVE-2026-103263 known 2026-10-01

https://github.com/advisories/GHSA-4cjq-6jh9-w2f5

Properties

cvss5.9
receipt
Source
GitHub advisories
Its words
5.9
Read by
field:cvss.score
Said since
2026-10-02 11:59 UTC
Last answered
2026-10-04 12:14 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-103263",
  "cvss": {
    "score": 5.9,
    "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 5.9,
      "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
    },
    "cvss_v4": {
      "score": 8.2,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-59",
      "name": "Improper Link Resolution Before File Access ('Link Following')"
    }
  ],
  "description": "Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user.",
  "ghsa_id": "GHSA-4cjq-6jh9-w2f5",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-4cjq-6jh9-w2f5",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-4cjq-6jh9-w2f5"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-103263"
    }
  ],
  "nvd_published_at": "2026-10-01T11:17:21Z",
  "published_at": "2026-10-01T12:31:17Z",
  "references": [
    "https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-103263",
    "https://github.com/tornadoweb/tornado/commit/437ab5f76565403b3403438d2e555d11f8128d32",
    "https://www.vulncheck.com/advisories/tornado-before-6.5.9-staticfilehandler-path-traversal-via-symlink",
    "https://github.com/advisories/GHSA-4cjq-6jh9-w2f5"
  ],
  "repository_advisory_url": null,
  "severity": "high",
  "source_code_location": "",
  "summary": "Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows...",
  "type": "unreviewed",
  "updated_at": "2026-10-01T12:31:18Z",
  "url": "https://api.github.com/advisories/GHSA-4cjq-6jh9-w2f5",
  "vulnerabilities": [],
  "withdrawn_at": null
}
cweCWE-59
receipt
Source
GitHub advisories
Its words
CWE-59
Read by
field:cwes[].cwe_id
Said since
2026-10-02 11:59 UTC
Last answered
2026-10-04 12:14 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-103263",
  "cvss": {
    "score": 5.9,
    "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 5.9,
      "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
    },
    "cvss_v4": {
      "score": 8.2,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-59",
      "name": "Improper Link Resolution Before File Access ('Link Following')"
    }
  ],
  "description": "Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user.",
  "ghsa_id": "GHSA-4cjq-6jh9-w2f5",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-4cjq-6jh9-w2f5",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-4cjq-6jh9-w2f5"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-103263"
    }
  ],
  "nvd_published_at": "2026-10-01T11:17:21Z",
  "published_at": "2026-10-01T12:31:17Z",
  "references": [
    "https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-103263",
    "https://github.com/tornadoweb/tornado/commit/437ab5f76565403b3403438d2e555d11f8128d32",
    "https://www.vulncheck.com/advisories/tornado-before-6.5.9-staticfilehandler-path-traversal-via-symlink",
    "https://github.com/advisories/GHSA-4cjq-6jh9-w2f5"
  ],
  "repository_advisory_url": null,
  "severity": "high",
  "source_code_location": "",
  "summary": "Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows...",
  "type": "unreviewed",
  "updated_at": "2026-10-01T12:31:18Z",
  "url": "https://api.github.com/advisories/GHSA-4cjq-6jh9-w2f5",
  "vulnerabilities": [],
  "withdrawn_at": null
}
severityhigh
From 7.0 to 8.9.
receipt
Source
GitHub advisories
Its words
high
Read by
field:severity
Said since
2026-10-02 11:59 UTC
Last answered
2026-10-04 12:14 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-103263",
  "cvss": {
    "score": 5.9,
    "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 5.9,
      "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
    },
    "cvss_v4": {
      "score": 8.2,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-59",
      "name": "Improper Link Resolution Before File Access ('Link Following')"
    }
  ],
  "description": "Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user.",
  "ghsa_id": "GHSA-4cjq-6jh9-w2f5",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-4cjq-6jh9-w2f5",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-4cjq-6jh9-w2f5"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-103263"
    }
  ],
  "nvd_published_at": "2026-10-01T11:17:21Z",
  "published_at": "2026-10-01T12:31:17Z",
  "references": [
    "https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-103263",
    "https://github.com/tornadoweb/tornado/commit/437ab5f76565403b3403438d2e555d11f8128d32",
    "https://www.vulncheck.com/advisories/tornado-before-6.5.9-staticfilehandler-path-traversal-via-symlink",
    "https://github.com/advisories/GHSA-4cjq-6jh9-w2f5"
  ],
  "repository_advisory_url": null,
  "severity": "high",
  "source_code_location": "",
  "summary": "Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows...",
  "type": "unreviewed",
  "updated_at": "2026-10-01T12:31:18Z",
  "url": "https://api.github.com/advisories/GHSA-4cjq-6jh9-w2f5",
  "vulnerabilities": [],
  "withdrawn_at": null
}

Text

Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows... Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user.