THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-32146 (HIGH 7.8) — Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows arbitrary file system modification during dependency download. Dependency names from gleam.toml and manifest.toml are incorporated into filesystem paths without sufficient validati

[NVD] CVE-2026-32146 (HIGH 7.8) — Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows arbitrary file system modification during dependency download. Dependency names from gleam.toml and manifest.toml are incorporated into filesystem paths without sufficient validati

lownvdPublished 2026-04-11

CVE-2026-32146 CVSS: 7.8 HIGH Published: 2026-04-11T14:16:03.640

Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows arbitrary file system modification during dependency download.

Dependency names from gleam.toml and manifest.toml are incorporated into filesystem paths without sufficient validation or confinement to the intended dependency directory

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-32146