CVE-2026-103263
Tornado before 6.5.9 StaticFileHandler Path Traversal via Symlink
CVSS Score
5.9
EPSS Score
0.0%
EPSS Percentile
0th
Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user.
| CWE | CWE-59 |
| Vendor | tornadoweb |
| Product | tornado |
| Published | Oct 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for tornadoweb tornado
Be the first to know when new medium vulnerabilities affecting tornadoweb tornado are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
tornadoweb / tornado
0 < 6.5.9
References
github.com: https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r github.com: https://github.com/tornadoweb/tornado/commit/437ab5f76565403b3403438d2e555d11f8128d32 vulncheck.com: https://www.vulncheck.com/advisories/tornado-before-6.5.9-staticfilehandler-path-traversal-via-symlink
Credits
๐ Yasha-ops ๐ iaohkut-from-NightWolf-Team