Impact
Tornado prior to version 6.5.9 suffers a path‑traversal flaw in its StaticFileHandler implementation. The handler follows symbolic links inside the configured static root without validating that the resolved target remains within that directory. As a result, an attacker who can trigger a request for a symlink can read arbitrary files located outside the intended root, such as configuration files, private keys and application secrets. This vulnerability can be leveraged by unauthenticated users, exposing sensitive data without the need for authentication or elevated privileges.
Affected Systems
Tornado Web applications built with Tornado version 6.5.8 or earlier are affected. Versions 6.5.9 and newer include a patch that prevents symbolic link traversal. The vulnerability applies to any deployment where a symlink inside the static file directory points to a location outside that directory. No specific operating system or architecture is mentioned, but the flaw is intrinsic to the Tornado framework.
Risk and Exploitability
The CVSS score is 8.2, indicating high severity. No EPSS data is available for this vulnerability, and it is not listed in the CISA KEV catalog. The flaw can be exploited with a simple HTTP GET request to the StaticFileHandler; no special privileges or authentication are required. Attackers can read arbitrary files as long as the process user has read permission, making this a significant confidentiality risk for operators who expose sensitive files through symlinks.
OpenCVE Enrichment