All 5 CVE vulnerabilities found in Gleam, with AI-generated Chinese analysis, references, and POCs.
Vendor: Gleam
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-59247 | Insufficient verification of Hex package metadata in Gleam CWE-345 | 7.6 | High | 2026-07-29 |
| CVE-2026-42795 | Symlink Following in Hex Package Export Allows Embedding Files Outside Project Root CWE-59 | - | - | 2026-06-02 |
| CVE-2026-32685 | Path Traversal in gleam docs build via documentation.pages Allows Arbitrary File Read and Write CWE-22 | - | - | 2026-06-02 |
| CVE-2026-43965 | Path Traversal in build/packages/packages.toml Allows Arbitrary Directory Deletion CWE-22 | - | - | 2026-06-02 |
| CVE-2026-32146 | Improper Path Validation in Git Dependency Handling Allows Arbitrary File System Modification CWE-22 | 7.5 | - | 2026-04-11 |
All 5 known CVE vulnerabilities affecting Gleam with full Chinese analysis, references, and POCs where available.