GHSA-C2M8-H5V5-343R: Path Traversal via Improper Link Resolution in Tornado StaticFileHandler
Vulnerability ID: GHSA-C2M8-H5V5-343R
CVSS Score: 7.5
Published: 2026-09-30
A path traversal and arbitrary file disclosure vulnerability exists in Tornado's StaticFileHandler. In versions prior to 6.5.9, the handler follows symbolic links that point outside of the configured root static directory. This behavior occurs because the handler performs lexical path validation rather than physical filesystem resolution, allowing unauthenticated remote attackers to read arbitrary files if they can access or control symbolic links within the served static root.
TL;DR
Tornado's StaticFileHandler prior to 6.5.9 is vulnerable to path traversal and arbitrary file disclosure. By performing lexical validation instead of physical path resolution, the application serves files targeted by symbolic links that point outside the static root.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-59, CWE-22
- Attack Vector: Network
- CVSS Score: 7.5 (High)
- Impact: Arbitrary File Disclosure
- Exploit Status: PoC / Functional (via unit tests)
- KEV Status: Not listed
Affected Systems
- Tornado web framework StaticFileHandler deployments
-
Tornado: < 6.5.9 (Fixed in:
6.5.9)
Code Analysis
Commit: 437ab5f
Fix path validation in StaticFileHandler to resolve symlinks and prevent directory escape.
Commit: f9f50b8
Follow-up fixes and improvements for symlink path traversal checks in StaticFileHandler.
Mitigation Strategies
- Upgrade to Tornado 6.5.9 or newer
- Ensure application directories contain no untrusted symbolic links
- Configure allowed_symlink_directory if out-of-bounds symlinks are functionally required
- Sanitize and block file uploads containing symlinks (e.g., zip archives)
Remediation Steps:
- Check current version: pip show tornado
- Execute upgrade: pip install --upgrade 'tornado>=6.5.9'
- Audit filesystem paths served by StaticFileHandler to locate unexpected symlinks
- For necessary symlinks, update tornado configuration initialization to define allowed_symlink_directory
References
Read the full report for GHSA-C2M8-H5V5-343R on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)