CVE-2026-108723
answer-me-with-html through 0.5.0 Symlink Following in Code Block src Embedding
CVSS Score
2.5
EPSS Score
0.0%
EPSS Percentile
0th
answer-me-with-html through 0.5.0 contains a link following vulnerability in the am CLI code block src= embedding, where localPath() checks only path text without resolving symlinks. Attackers can ship a repository with a symlink pointing outside the checkout so am render embeds readable external files into generated HTML, disclosing them when shared.
| CWE | CWE-59 |
| Vendor | qingyuna |
| Product | answer-me-with-html |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for qingyuna answer-me-with-html
Be the first to know when new low vulnerabilities affecting qingyuna answer-me-with-html are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N Attack Vector
Local
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected Versions
QingYunA / answer-me-with-html
0 โค 0.5.0
References
hackmd.io: https://hackmd.io/@haind/answer-me-with-html-code-src-symlink-escape github.com: https://github.com/QingYunA/answer-me-with-html/blob/b275eba8d4cc49bcb4bbc28459863f4b49a480f9/src/code.js#L74-L105 github.com: https://github.com/QingYunA/answer-me-with-html vulncheck.com: https://www.vulncheck.com/advisories/answer-me-with-html-through-0.5.0-symlink-following-in-code-block-src-embedding
Credits
HaiND from the Post and Telecommunication Institute of Technology