OVERVIEW CVE-2026-32146 is an improper path validation vulnerability in the Gleam compiler affecting versions 1.9.0-rc1 through 1.15.4. The vulnerability exists in the compiler's handling of git dependencies, where dependency names from configuration files are incorporated into filesystem paths without proper validation. This allows attackers to use path traversal techniques or absolute paths to target locations outside the intended dependency directory during the dependency download and resolution phase. SEVERITY The attack vector requires a malicious direct or transitive git dependency to be introduced into a project's dependency chain, making it a supply chain-oriented threat. Attack complexity is considered low, as exploitation requires only crafting a specially formatted dependency name. The potential impact is significant: an attacker can delete and overwrite arbitrary filesystem directories, including absolute paths specified by the attacker, causing data loss. In certain environments, this could be leveraged further to achieve code execution by overwriting git hooks or shell configuration files. The FAUCET Risk Score of 51.0/100 reflects moderate concern, though the CVSS and EPSS scores indicate relatively low baseline statistical risk across the broader vulnerability landscape. EXPLOITATION STATUS There is no evidence of active exploitation. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities catalog, and exploit code is not publicly available. The low EPSS score of 0.00027 suggests minimal community attention and threat actor interest at this time. However, given the supply chain nature and destructive capabilities of the vulnerability, organizations using affected Gleam versions should prioritize patching to version 1.15.4 or later.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.9.0, < 1.15.4CPE matchmatch criteria | cpe:2.3:a:lpil:gleam:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.