CVE-2026-32146Disclosure(lpil / gleam)

LOWCVSS 7.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows arbitrary file system modification during dependency download. Dependency names from gleam.toml and manifest.toml are incorporated into filesystem paths without sufficient validation or confinement to the intended dependency directory, allowing attacker-controlled paths (via relative traversal such as ../ or absolute paths) to target filesystem locations outside that directory. When resolving git dependencies (e.g. via gleam deps download), the computed path is used for filesystem operations including directory deletion and creation. This vulnerability occurs during the dependency resolution and download phase, which is generally expected to be limited to fetching and preparing dependencies within a confined directory. A malicious direct or transitive git dependency can exploit this issue to delete and overwrite arbitrary directories outside the intended dependency directory, including attacker-chosen absolute paths, potentially causing data loss. In some environments, this may be further leveraged to achieve code execution, for example by overwriting git hooks or shell configuration files. This issue affects Gleam from 1.9.0-rc1 until 1.15.4.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gleam

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
gleam

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-11: 3Technical Details · 2026-04-11: 304-11
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-32146 Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows arbitrary file system modification during dependency download. Dep… https://www.cve.org/CVERecord?id=CVE-2026-32146

    Post summary

    A newly disclosed vulnerability, CVE-2026-32146, in the Gleam compiler allows arbitrary file system modifications due to improper path validation during dependency downloads; no PoC, exploit, or patch details are provided.

    000101.0K
    57.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-32146 Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows arbitrary file system modification during dependency download. Dep… https://www.cve.org/CVERecord?id=CVE-2026-32146 ----- Traducción: CVE-2026-32146 vul… http://infoflow.cloud`

    Post summary

    Announces CVE-2026-32146, an improper path validation vulnerability in the Gleam compiler that permits arbitrary filesystem modifications during git dependency downloads.

    0000058
    71 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-32146 Path Traversal Vulnerability in Gleam Compiler Git Dependency Resolution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32146

    Post summary

    The text cites a path‑traversal flaw in Gleam Compiler’s Git dependency resolver but provides no PoC, exploit, or mitigation details.

    0000053
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applpilgleam---

Explore more