Junglewise Threat Intelligence

CVE-2026-32685: Gleam path traversal in documentation pages handling

CVE-2026-32685 · Severity: info · CVSS 4.6 · Published 2026-06-02

Technologies: Gleam.

Executive brief

A vulnerability in the Gleam programming language's documentation tool could allow a malicious project to read or write files outside of its intended directory. If a developer runs the documentation build command on an untrusted project, sensitive local files could be leaked into the generated documentation or arbitrary files could be overwritten on their system. This poses a risk to the confidentiality of developer data and the integrity of the local file system.

Technical details

A path traversal vulnerability exists in Gleam's handling of custom documentation pages defined in the 'gleam.toml' configuration file. The 'documentation.pages[].path' and 'documentation.pages[].source' fields are not sufficiently validated, allowing an attacker to use relative path components (e.g., '../') to escape the intended project and output directories. By convincing a victim to run 'gleam docs build' on a malicious project, an attacker can read arbitrary local files and embed them in the documentation output, or write generated documentation files to locations outside the 'build/dev/docs/' directory. The issue was addressed in version 1.17.0 by implementing stricter path validation during deserialization.

Affected products

  • Gleam Gleam 1.16.0 to 1.17.0

Timeline

  • 2026-04-25: other: Initial fix developed
  • 2026-06-02: disclosed: Vulnerability disclosed and CVE assigned
  • 2026-06-02: patched: Fix released in version 1.17.0

References