CVE-2026-103263
8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Summary
Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| tornadoweb | tornado | 0 < 6.5.9 | affected |
| tornadoweb | tornado | 6.5.9 | unaffected |
Weaknesses
- CWE-59: Improper Link Resolution Before File Access ('Link Following')
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: no
- Technical Impact: partial
Additional References
References
- https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r
- https://github.com/tornadoweb/tornado/commit/437ab5f76565403b3403438d2e555d11f8128d32
- https://www.vulncheck.com/advisories/tornado-before-6.5.9-staticfilehandler-path-traversal-via-symlink
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.