Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-103263— Tornado before 6.5.9 StaticFileHandler Path Traversal via Symlink

Quick assessment

Affected
tornadoweb tornado
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Tornado 6.5.9 之前的版本在 中存在一个路径遍历漏洞。该组件在处理静态文件时,会跟随位于静态根目录内的符号链接(symlink),但未验证解析后的目标路径是否仍保留在静态根目录内。如果静态目录内部存在指向该目录外部的符号链接,未经身份验证的攻击者即可通过请求这些符号链接来读取进程用户可访问的文件,例如配置文件、私钥以及应用程序密钥等敏感信息。

CVSS 5.9 · Medium

Possible ATT&CK Techniques 1 AI

T1083 · File and Directory Discovery
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-103263

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Tornado before 6.5.9 StaticFileHandler Path Traversal via Symlink
Source: CVE Program / CVE List V5
Vulnerability Description
Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在文件访问前对链接解析不恰当(链接跟随)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
tornadoweb tornado 0 ~ 6.5.9 -

II. Public POCs for CVE-2026-103263

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-103263

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-103263 (1)

Vendor Advisories for CVE-2026-103263 (2)

Same Patch Batch · tornadoweb · 2026-10-01 · 3 CVEs total

CVE-2026-103262 7.5 HIGH Tornado before 6.5.9 Denial of Service via CurlAsyncHTTPClient
CVE-2026-103261 5.3 MEDIUM Tornado before 6.5.9 Denial of Service via Query String

IV. Related Vulnerabilities

V. Comments for CVE-2026-103263

No comments yet


Leave a comment