Medium severity5.9NVD Advisory· Published Oct 1, 2026· Updated Oct 1, 2026
CVE-2026-103263
CVE-2026-103263
Description
Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user.
Affected products
1- Range: <6.5.9
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.