What happened
Symlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in the generated package tarball. The file collection helpers (gleam_files, native_files, private_files) in compiler-cli/src/fs.rs use follow_links(true) when walking publishable directories such as src/ and priv/. The collected paths are added to the package archive via add_path_to_tar in compiler-cli/src/publish.rs without verifying that the resolved target remains within the project root. A symlink placed under a publishable directory will cause gleam export hex-tarball or gleam publish to embed the contents of the symlink target into the generated Hex package. An attacker with write access to the project repository can place a symlink in src/ or priv/ pointing to an arbitrary file. When a maintainer or CI pipeline runs gleam publish or gleam export hex-tarball, local files readable by the publisher (such as secrets, tokens, or SSH keys) are silently embedded into the published package artifact. This issue affects Gleam from 0.10.0-rc1 until 1.17.0.
Affected versions
Gleam: 0.10.0-rc1 through before 1.17.0 (semver); c82a2d83bd0c06cafdc196820deb3f89a9b3ff7c through before 6435a5528b9ae0449e2f32be579641ec485f6866 (git); v0.10.0-rc1-elixir through before v1.17.0-elixir (other); v0.10.0-rc1-erlang through before v1.17.0-erlang (other); v0.10.0-rc1-node through before v1.17.0-node (other); v0.10.0-rc1-node-slim through before v1.17.0-node-slim (other); v0.10.0-rc1-elixir-slim through before v1.17.0-elixir-slim (other); v0.10.0-rc1-erlang-slim through before v1.17.0-erlang-slim (other); v0.10.0-rc1-erlang-alpine through before v1.17.0-erlang-alpine (other); v0.10.0-rc1-elixir-alpine through before v1.17.0-elixir-alpine (other); v0.10.0-rc1-node-alpine through before v1.17.0-node-alpine (other); v0.10.0-rc1-scratch through before v1.17.0-scratch (other) Fixed: See vendor advisory.
Why it matters
Review the vendor advisory and exposure of the affected product to determine operational impact.
Detection & mitigation
- Apply vendor-provided updates or mitigations.
- Review affected product exposure and access logs.
Public PoC references
No public PoC reference has passed the current publication threshold.