Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-56651— Arbitrary File Overwrite via Symlink Following in dool project

Quick assessment

Affected
scottchiefbaker dool
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Dool 在 1.3.8 及更早版本中,当使用 “--devel” 标志时,易受符号链接跟随(symlink following)漏洞影响。原因是应用程序在打开日志文件时未使用 标志。本地攻击者可以通过在预期的日志文件路径创建一个指向敏感文件的符号链接来利用此漏洞,导致 dool 将日志数据截断并覆盖目标文件。如果 dool 以较高权限(如 root)运行,其影响尤为严重。 该问题已通过拉取请求 #116 得到修复。

CVSS 2.0 · Low

Possible ATT&CK Techniques 1 AI

T1078 · Valid Accounts

Affected Version Matrix 1

VendorProduct Version RangeStatus
scottchiefbaker dool ≤ 1.3.8 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-56651

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Arbitrary File Overwrite via Symlink Following in dool project
Source: CVE Program / CVE List V5
Vulnerability Description
Dool in versions up to 1.3.8 is vulnerable to symlink following when the "--devel" flag is used, as the application opens a log file without the "O_NOFOLLOW" flag. A local attacker can exploit this by creating a symlink at the expected log file path pointing to a sensitive file, causing dool to truncate and overwrite the target file with log data, which is especially impactful if dool is run with elevated privileges. The issue was addressed by pull request #116
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
在文件访问前对链接解析不恰当(链接跟随)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
scottchiefbaker dool 0 ~ 1.3.8 -

II. Public POCs for CVE-2026-56651

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-56651

登录查看更多情报信息。

Patches & Fixes for CVE-2026-56651 (1)

Security Blog Posts for CVE-2026-56651 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-56651

No comments yet


Leave a comment