B3NCLOUD ARTICLE INTELLIGENCE

ARTICLEVIEW

Zurück zu News

[Medium] CVE-2026-42795 – Symlink following vulnerability in Gleam's Hex package export allows files outsi...

Medium CVE-2026-42795 Symlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in the generated package tarball. The file collection helpers (gleam_files, native_files, private_files) in compiler-cli/src/fs.rs use follow_links(true) when...

Original-Artikel öffnen Zurück zur Übersicht