๐Ÿ” CVE Alert

CVE-2026-103263

MEDIUM 5.9

Tornado before 6.5.9 StaticFileHandler Path Traversal via Symlink

CVSS Score
5.9
EPSS Score
0.0%
EPSS Percentile
0th

Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user.

CWE CWE-59
Vendor tornadoweb
Product tornado
Published Oct 1, 2026
Stay Ahead of the Next One

Get instant alerts for tornadoweb tornado

Be the first to know when new medium vulnerabilities affecting tornadoweb tornado are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

tornadoweb / tornado
0 < 6.5.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r github.com: https://github.com/tornadoweb/tornado/commit/437ab5f76565403b3403438d2e555d11f8128d32 vulncheck.com: https://www.vulncheck.com/advisories/tornado-before-6.5.9-staticfilehandler-path-traversal-via-symlink

Credits

๐Ÿ” Yasha-ops ๐Ÿ” iaohkut-from-NightWolf-Team