THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-32685 — Path traversal vulnerability in Gleam's handling of custom documentation pages allows arbitrary file read and file write outside the intended documentation output directory. The documentation.pages entries from gleam.toml are incorporated into filesystem paths without sufficient

[NVD] CVE-2026-32685 — Path traversal vulnerability in Gleam's handling of custom documentation pages allows arbitrary file read and file write outside the intended documentation output directory. The documentation.pages entries from gleam.toml are incorporated into filesystem paths without sufficient

lownvdPublished 2026-06-02

CVE-2026-32685 CVSS: None Published: 2026-06-02T14:16:50.610

Path traversal vulnerability in Gleam's handling of custom documentation pages allows arbitrary file read and file write outside the intended documentation output directory.

The documentation.pages entries from gleam.toml are incorporated into filesystem paths without sufficient validation or confinement to the intended project and do

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-32685