Executive brief
Gleam is a programming language and toolchain for the Erlang ecosystem. A vulnerability in its dependency management system allows a malicious project to delete arbitrary folders on a developer's computer. If a user runs the standard dependency download command on a compromised project, the tool can be tricked into recursively deleting sensitive data, source code, or system directories without warning.
Technical details
A path traversal vulnerability exists in Gleam's compiler-cli within the dependency management logic. The function `LocalPackages::read_from_disc` reads package keys from `build/packages/packages.toml` without validation. These keys are passed to `paths.build_packages_package()`, which joins them with the project build directory, and subsequently to `fs::delete_directory` (calling `remove_dir_all`). Because the keys can contain absolute paths or relative traversal sequences (e.g., `../`), an attacker can specify any directory on the filesystem for recursive deletion. Exploitation occurs when a victim runs `gleam deps download` on a project containing a malicious, committed `packages.toml` file. The issue is fixed in version 1.17.0.
Affected products
- Gleam Gleam >= 0.18.0-rc1, < 1.17.0
Timeline
- 2026-05-05: other: Patch authored
- 2026-06-02: patched: Patch committed to main branch
- 2026-06-02: disclosed: CVE published
- 2026-06-02: advisory: GitHub Security Advisory published