Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-32146

32
FAUCET Score

OVERVIEW CVE-2026-32146 is an improper path validation vulnerability in the Gleam compiler affecting versions 1.9.0-rc1 through 1.15.4. The vulnerability exists in the compiler's handling of git dependencies, where dependency names from configuration files are incorporated into filesystem paths without proper validation. This allows attackers to use path traversal techniques or absolute paths to target locations outside the intended dependency directory during the dependency download and resolution phase. SEVERITY The attack vector requires a malicious direct or transitive git dependency to be introduced into a project's dependency chain, making it a supply chain-oriented threat. Attack complexity is considered low, as exploitation requires only crafting a specially formatted dependency name. The potential impact is significant: an attacker can delete and overwrite arbitrary filesystem directories, including absolute paths specified by the attacker, causing data loss. In certain environments, this could be leveraged further to achieve code execution by overwriting git hooks or shell configuration files. The FAUCET Risk Score of 51.0/100 reflects moderate concern, though the CVSS and EPSS scores indicate relatively low baseline statistical risk across the broader vulnerability landscape. EXPLOITATION STATUS There is no evidence of active exploitation. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities catalog, and exploit code is not publicly available. The low EPSS score of 0.00027 suggests minimal community attention and threat actor interest at this time. However, given the supply chain nature and destructive capabilities of the vulnerability, organizations using affected Gleam versions should prioritize patching to version 1.15.4 or later.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.9.0, < 1.15.4CPE matchmatch criteria
cpe:2.3:a:lpil:gleam:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.3HIGH

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
ACTIVE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
HIGH
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
15.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 14th percentile among its peer group of 11,621 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

access.redhat.com / security/cve/CVE-2026-32146
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-32146.json
cna.erlef.org / cves/CVE-2026-32146.html
Third Party Advisory
github.com / gleam-lang/gleam/commit/1aa5d8e594b0aa240bb213fce6ee19c65e6d5bcf
Patch
github.com / gleam-lang/gleam/commit/2dc0467f822c75de94697a912755d172928ee40a
Patch
github.com / gleam-lang/gleam/security/advisories/GHSA-vq5j-55vx-wq8j
ExploitVendor Advisory
osv.dev / vulnerability/EEF-CVE-2026-32146
Third Party Advisory