« Volver al listado

CVE-2026-42795

Estado: AplazadaMedia (5.1)—

Symlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in the generated package tarball.

The file collection helpers (gleam_files, native_files, private_files) in compiler-cli/src/fs.rs use follow_links(true) when walking publishable directories such as src/ and priv/. The collected paths are added to the package archive via add_path_to_tar in compiler-cli/src/publish.rs without verifying that the resolved target remains within the project root. A symlink placed under a publishable directory will cause gleam export hex-tarball or gleam publish to embed the contents of the symlink target into the generated Hex package.

Leer descripción completaMostrar menos

An attacker with write access to the project repository can place a symlink in src/ or priv/ pointing to an arbitrary file. When a maintainer or CI pipeline runs gleam publish or gleam export hex-tarball, local files readable by the publisher (such as secrets, tokens, or SSH keys) are silently embedded into the published package artifact.

This issue affects Gleam from 0.10.0-rc1 until 1.17.0.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-42795",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-42795",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-02T15:04:06.195456Z"
        }
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 5.1,
          "Automatable": "NOT_DEFINED",
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "ACTIVE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "LOW",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "NONE",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "NONE",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "HIGH",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:gleam-lang:gleam:*:*:*:*:*:*:*:*"
          ],
          "vendor": "Gleam",
          "modules": [
            "compiler-cli"
          ],
          "product": "Gleam",
          "versions": [
            {
              "status": "affected",
              "version": "0.10.0-rc1",
              "lessThan": "1.17.0",
              "versionType": "semver"
            }
          ],
          "packageURL": "pkg:software-id/gleam.run/gleam",
          "packageName": "gleam",
          "programFiles": [
            "compiler-cli/src/fs.rs",
            "compiler-cli/src/publish.rs"
          ],
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "compiler_cli::fs::gleam_files"
            },
            {
              "name": "compiler_cli::fs::native_files"
            },
            {
              "name": "compiler_cli::fs::private_files"
            },
            {
              "name": "compiler_cli::publish::project_files"
            },
            {
              "name": "compiler_cli::publish::add_path_to_tar"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:gleam-lang:gleam:*:*:*:*:*:*:*:*"
          ],
          "repo": "https://github.com/gleam-lang/gleam",
          "vendor": "Gleam",
          "modules": [
            "compiler-cli"
          ],
          "product": "Gleam",
          "versions": [
            {
              "status": "affected",
              "version": "0.10.0-rc1",
              "lessThan": "1.17.0",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "c82a2d83bd0c06cafdc196820deb3f89a9b3ff7c",
              "lessThan": "6435a5528b9ae0449e2f32be579641ec485f6866",
              "versionType": "git"
            }
          ],
          "packageURL": "pkg:github/gleam-lang/gleam",
          "packageName": "gleam-lang/gleam",
          "programFiles": [
            "compiler-cli/src/fs.rs",
            "compiler-cli/src/publish.rs"
          ],
          "collectionURL": "https://github.com",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "compiler_cli::fs::gleam_files"
            },
            {
              "name": "compiler_cli::fs::native_files"
            },
            {
              "name": "compiler_cli::fs::private_files"
            },
            {
              "name": "compiler_cli::publish::project_files"
            },
            {
              "name": "compiler_cli::publish::add_path_to_tar"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:gleam-lang:gleam:*:*:*:*:*:*:*:*"
          ],
          "vendor": "Gleam",
          "modules": [
            "compiler-cli"
          ],
          "product": "Gleam",
          "versions": [
            {
              "status": "affected",
              "version": "v0.10.0-rc1-elixir",
              "lessThan": "v1.17.0-elixir",
              "versionType": "other"
            },
            {
              "status": "affected",
              "version": "v0.10.0-rc1-erlang",
              "lessThan": "v1.17.0-erlang",
              "versionType": "other"
            },
            {
              "status": "affected",
              "version": "v0.10.0-rc1-node",
              "lessThan": "v1.17.0-node",
              "versionType": "other"
            },
            {
              "status": "affected",
              "version": "v0.10.0-rc1-node-slim",
              "lessThan": "v1.17.0-node-slim",
              "versionType": "other"
            },
            {
              "status": "affected",
              "version": "v0.10.0-rc1-elixir-slim",
              "lessThan": "v1.17.0-elixir-slim",
              "versionType": "other"
            },
            {
              "status": "affected",
              "version": "v0.10.0-rc1-erlang-slim",
              "lessThan": "v1.17.0-erlang-slim",
              "versionType": "other"
            },
            {
              "status": "affected",
              "version": "v0.10.0-rc1-erlang-alpine",
              "lessThan": "v1.17.0-erlang-alpine",
              "versionType": "other"
            },
            {
              "status": "affected",
              "version": "v0.10.0-rc1-elixir-alpine",
              "lessThan": "v1.17.0-elixir-alpine",
              "versionType": "other"
            },
            {
              "status": "affected",
              "version": "v0.10.0-rc1-node-alpine",
              "lessThan": "v1.17.0-node-alpine",
              "versionType": "other"
            },
            {
              "status": "affected",
              "version": "v0.10.0-rc1-scratch",
              "lessThan": "v1.17.0-scratch",
              "versionType": "other"
            }
          ],
          "packageURL": "pkg:oci/gleam?repository_url=ghcr.io/gleam-lang",
          "packageName": "gleam-lang/gleam",
          "programFiles": [
            "compiler-cli/src/fs.rs",
            "compiler-cli/src/publish.rs"
          ],
          "collectionURL": "https://ghcr.io",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "compiler_cli::fs::gleam_files"
            },
            {
              "name": "compiler_cli::fs::native_files"
            },
            {
              "name": "compiler_cli::fs::private_files"
            },
            {
              "name": "compiler_cli::publish::project_files"
            },
            {
              "name": "compiler_cli::publish::add_path_to_tar"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-06-02T14:16:53.883",
  "references": [
    {
      "url": "https://cna.erlef.org/cves/CVE-2026-42795.html",
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://github.com/gleam-lang/gleam/commit/6435a5528b9ae0449e2f32be579641ec485f6866",
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://github.com/gleam-lang/gleam/security/advisories/GHSA-qhh5-fg4c-8gqc",
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://osv.dev/vulnerability/EEF-CVE-2026-42795",
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://github.com/gleam-lang/gleam/security/advisories/GHSA-qhh5-fg4c-8gqc",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
      "description": [
        {
          "lang": "en",
          "value": "CWE-59"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Symlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in the generated package tarball.\n\nThe file collection helpers (gleam_files, native_files, private_files) in compiler-cli/src/fs.rs use follow_links(true) when walking publishable directories such as src/ and priv/. The collected paths are added to the package archive via add_path_to_tar in compiler-cli/src/publish.rs without verifying that the resolved target remains within the project root. A symlink placed under a publishable directory will cause gleam export hex-tarball or gleam publish to embed the contents of the symlink target into the generated Hex package.\n\nAn attacker with write access to the project repository can place a symlink in src/ or priv/ pointing to an arbitrary file. When a maintainer or CI pipeline runs gleam publish or gleam export hex-tarball, local files readable by the publisher (such as secrets, tokens, or SSH keys) are silently embedded into the published package artifact.\n\nThis issue affects Gleam from 0.10.0-rc1 until 1.17.0."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de seguimiento de enlaces simbólicos en la exportación de paquetes Hex de Gleam permite que archivos fuera de la raíz del proyecto sean incrustados en el tarball del paquete generado.\n\nLos ayudantes de recolección de archivos (gleam_files, native_files, private_files) en compiler-cli/src/fs.rs usan follow_links(true) al recorrer directorios publicables como src/ y priv/. Las rutas recolectadas se añaden al archivo del paquete a través de add_path_to_tar en compiler-cli/src/publish.rs sin verificar que el objetivo resuelto permanezca dentro de la raíz del proyecto. Un enlace simbólico colocado bajo un directorio publicable hará que gleam export hex-tarball o gleam publish incrusten el contenido del objetivo del enlace simbólico en el paquete Hex generado.\n\nUn atacante con acceso de escritura al repositorio del proyecto puede colocar un enlace simbólico en src/ o priv/ apuntando a un archivo arbitrario. Cuando un mantenedor o una tubería de CI ejecuta gleam publish o gleam export hex-tarball, los archivos locales legibles por el publicador (como secretos, tokens o claves SSH) son incrustados silenciosamente en el artefacto del paquete publicado.\n\nEste problema afecta a Gleam desde 0.10.0-rc1 hasta 1.17.0."
    }
  ],
  "lastModified": "2026-09-08T01:17:30.483",
  "sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
}