---
id: CVE-2026-103263
title: >-
  Tornado before 6.5.9 contains a path traversal vulnerability in
  StaticFileHandler that follows symbolic links inside the static root without
  confirming the resolved target stays within it
summary: >-
  Tornado before 6.5.9 contains a path traversal vulnerability in
  StaticFileHandler that follows symbolic links inside the static root without
  confirming the resolved target stays within it. When a symlink pointing
  outside the static direc…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-59
vendor: tornadoweb
product: tornado
affected:
  - tornado < 6.5.9
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T11:17:21.363'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103263'
references:
  - url: >-
      https://github.com/tornadoweb/tornado/commit/437ab5f76565403b3403438d2e555d11f8128d32
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/tornado-before-6.5.9-staticfilehandler-path-traversal-via-symlink
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-01T11:42:53.805Z'
---

## Overview

Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
