THREAT OPS › Threat News › [NVD] CVE-2026-32146 (HIGH 7.8) — Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows arbitrary file system modification during dependency download.
Dependency names from gleam.toml and manifest.toml are incorporated into filesystem paths without sufficient validati
[NVD] CVE-2026-32146 (HIGH 7.8) — Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows arbitrary file system modification during dependency download. Dependency names from gleam.toml and manifest.toml are incorporated into filesystem paths without sufficient validati
CVE-2026-32146 CVSS: 7.8 HIGH Published: 2026-04-11T14:16:03.640
Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows arbitrary file system modification during dependency download.
Dependency names from gleam.toml and manifest.toml are incorporated into filesystem paths without sufficient validation or confinement to the intended dependency directory
Indicators of compromise
- CVE-2026-32146cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-32146