Low severity2.5NVD Advisory· Published Oct 11, 2026
CVE-2026-108723
CVE-2026-108723
Description
answer-me-with-html through 0.5.0 contains a link following vulnerability in the am CLI code block src= embedding, where localPath() checks only path text without resolving symlinks. Attackers can ship a repository with a symlink pointing outside the checkout so am render embeds readable external files into generated HTML, disclosing them when shared.
Affected products
1- Range: <=0.5.0
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.