Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows...
zetlyn/cve-ghsa vulnerability ghsa GHSA-4cjq-6jh9-w2f5 cve CVE-2026-103263 known 2026-10-01
https://github.com/advisories/GHSA-4cjq-6jh9-w2f5
Properties
| cvss | 5.9receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-103263",
"cvss": {
"score": 5.9,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
"cvss_severities": {
"cvss_v3": {
"score": 5.9,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
"cvss_v4": {
"score": 8.2,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-59",
"name": "Improper Link Resolution Before File Access ('Link Following')"
}
],
"description": "Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user.",
"ghsa_id": "GHSA-4cjq-6jh9-w2f5",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-4cjq-6jh9-w2f5",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-4cjq-6jh9-w2f5"
},
{
"type": "CVE",
"value": "CVE-2026-103263"
}
],
"nvd_published_at": "2026-10-01T11:17:21Z",
"published_at": "2026-10-01T12:31:17Z",
"references": [
"https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r",
"https://nvd.nist.gov/vuln/detail/CVE-2026-103263",
"https://github.com/tornadoweb/tornado/commit/437ab5f76565403b3403438d2e555d11f8128d32",
"https://www.vulncheck.com/advisories/tornado-before-6.5.9-staticfilehandler-path-traversal-via-symlink",
"https://github.com/advisories/GHSA-4cjq-6jh9-w2f5"
],
"repository_advisory_url": null,
"severity": "high",
"source_code_location": "",
"summary": "Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows...",
"type": "unreviewed",
"updated_at": "2026-10-01T12:31:18Z",
"url": "https://api.github.com/advisories/GHSA-4cjq-6jh9-w2f5",
"vulnerabilities": [],
"withdrawn_at": null
} |
|---|---|
| cwe | CWE-59receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-103263",
"cvss": {
"score": 5.9,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
"cvss_severities": {
"cvss_v3": {
"score": 5.9,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
"cvss_v4": {
"score": 8.2,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-59",
"name": "Improper Link Resolution Before File Access ('Link Following')"
}
],
"description": "Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user.",
"ghsa_id": "GHSA-4cjq-6jh9-w2f5",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-4cjq-6jh9-w2f5",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-4cjq-6jh9-w2f5"
},
{
"type": "CVE",
"value": "CVE-2026-103263"
}
],
"nvd_published_at": "2026-10-01T11:17:21Z",
"published_at": "2026-10-01T12:31:17Z",
"references": [
"https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r",
"https://nvd.nist.gov/vuln/detail/CVE-2026-103263",
"https://github.com/tornadoweb/tornado/commit/437ab5f76565403b3403438d2e555d11f8128d32",
"https://www.vulncheck.com/advisories/tornado-before-6.5.9-staticfilehandler-path-traversal-via-symlink",
"https://github.com/advisories/GHSA-4cjq-6jh9-w2f5"
],
"repository_advisory_url": null,
"severity": "high",
"source_code_location": "",
"summary": "Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows...",
"type": "unreviewed",
"updated_at": "2026-10-01T12:31:18Z",
"url": "https://api.github.com/advisories/GHSA-4cjq-6jh9-w2f5",
"vulnerabilities": [],
"withdrawn_at": null
} |
| severity | high From 7.0 to 8.9. receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-103263",
"cvss": {
"score": 5.9,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
"cvss_severities": {
"cvss_v3": {
"score": 5.9,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
"cvss_v4": {
"score": 8.2,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-59",
"name": "Improper Link Resolution Before File Access ('Link Following')"
}
],
"description": "Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user.",
"ghsa_id": "GHSA-4cjq-6jh9-w2f5",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-4cjq-6jh9-w2f5",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-4cjq-6jh9-w2f5"
},
{
"type": "CVE",
"value": "CVE-2026-103263"
}
],
"nvd_published_at": "2026-10-01T11:17:21Z",
"published_at": "2026-10-01T12:31:17Z",
"references": [
"https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r",
"https://nvd.nist.gov/vuln/detail/CVE-2026-103263",
"https://github.com/tornadoweb/tornado/commit/437ab5f76565403b3403438d2e555d11f8128d32",
"https://www.vulncheck.com/advisories/tornado-before-6.5.9-staticfilehandler-path-traversal-via-symlink",
"https://github.com/advisories/GHSA-4cjq-6jh9-w2f5"
],
"repository_advisory_url": null,
"severity": "high",
"source_code_location": "",
"summary": "Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows...",
"type": "unreviewed",
"updated_at": "2026-10-01T12:31:18Z",
"url": "https://api.github.com/advisories/GHSA-4cjq-6jh9-w2f5",
"vulnerabilities": [],
"withdrawn_at": null
} |
Text
Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows...
Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user.