๐Ÿ” CVE Alert

CVE-2026-108723

LOW 2.5

answer-me-with-html through 0.5.0 Symlink Following in Code Block src Embedding

CVSS Score
2.5
EPSS Score
0.0%
EPSS Percentile
0th

answer-me-with-html through 0.5.0 contains a link following vulnerability in the am CLI code block src= embedding, where localPath() checks only path text without resolving symlinks. Attackers can ship a repository with a symlink pointing outside the checkout so am render embeds readable external files into generated HTML, disclosing them when shared.

CWE CWE-59
Vendor qingyuna
Product answer-me-with-html
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for qingyuna answer-me-with-html

Be the first to know when new low vulnerabilities affecting qingyuna answer-me-with-html are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
Attack Vector
Local
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

QingYunA / answer-me-with-html
0 โ‰ค 0.5.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
hackmd.io: https://hackmd.io/@haind/answer-me-with-html-code-src-symlink-escape github.com: https://github.com/QingYunA/answer-me-with-html/blob/b275eba8d4cc49bcb4bbc28459863f4b49a480f9/src/code.js#L74-L105 github.com: https://github.com/QingYunA/answer-me-with-html vulncheck.com: https://www.vulncheck.com/advisories/answer-me-with-html-through-0.5.0-symlink-following-in-code-block-src-embedding

Credits

HaiND from the Post and Telecommunication Institute of Technology