Link Following Affecting grafana13.1 package, versions *


Severity

Recommended
0.0
medium
0
10

Based on Red Hat Enterprise Linux security rating.

Threat Intelligence

EPSS
0.35% (26th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RHEL10-GRAFANA131-20241595
  • published29 Sept 2026
  • disclosed26 Sept 2026

Introduced: 26 Sep 2026

NewCVE-2026-100690  (opens in a new tab)
CWE-59  (opens in a new tab)

How to fix?

There is no fixed version for RHEL:10 grafana13.1.

NVD Description

Note: Versions mentioned in the description apply only to the upstream grafana13.1 package and not the grafana13.1 package as distributed by RHEL. See How to fix? for RHEL:10 relevant fixed versions and status.

Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js permission model to restrict file system reads to the project directory and configured mounts. Because the Node.js permission model validates only the lexical path and follows symbolic links that point outside the allowed set, Hugo did not detect symlinks escaping the sandbox. An attacker who can contribute content to a Hugo project (for example via a pull request) can commit a symlink such as assets/css/x.css -> /etc/passwd together with a PostCSS plugin that reads it, allowing any file readable by the Hugo build process to be disclosed and potentially embedded in the published site. This affects builds using the default security configuration; projects that do not invoke Node.js tools are unaffected. Fixed in v0.166.0, which scans allowed paths and fails the build when a symbolic link resolves outside them.

CVSS Base Scores

version 3.1