Sceawere
Vulnerability Detail
CVE-2026-108723UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Arbitrary File Disclosure in answer-me-with-html
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 2.5
- Creation Date
- 4h ago
- Vendor
- QingYunA
- Product
- answer-me-with-html
- Attack Type
- Improper Link Resolution Before File Access ('Link Following')
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
answer-me-with-html through 0.5.0 contains a link following vulnerability in the am CLI code block src= embedding, where localPath() checks only path text without resolving symlinks. Attackers can ship a repository with a symlink pointing outside the checkout so am render embeds readable external files into generated HTML, disclosing them when shared.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "2.5",
"pubDate": "2026-10-11T13:17:15.840Z",
"pubdate": "2026-10-11T13:17:15.840Z",
"executiveSummary": "The vulnerability identified in answer-me-with-html versions 0.5.0 and earlier involves a Path Traversal via symlink exploitation. This flaw resides within the command-line interface (CLI) implementation specifically concerning the handling of src= embedding directives in code blocks.\nThe vulnerability allows an attacker to gain unauthorized read access to arbitrary files on the local filesystem by leveraging maliciously crafted symlinks within a repository.\nWhen a user processes a repository containing these crafted symlinks, the am tool inadvertently resolves and embeds sensitive local file content into the generated HTML output.\nThis represents a significant security risk, as the rendered HTML, when shared or hosted, results in the unintended disclosure of potentially sensitive system files or credentials.\nThe attacker requires the ability to commit files to a repository that is subsequently processed by the vulnerable am tool. No specific network exposure is required, as the exploit is triggered during the static content generation process on the victim's local machine or CI/CD environment.",
"technicalDetails": "The root cause of this vulnerability is an improper input validation mechanism within the localPath() function of the am CLI. While the function performs basic path string analysis to ensure the requested resource resides within the expected working directory, it fails to account for symbolic links (symlinks) within the filesystem.\nBecause localPath() only inspects the literal path text, it neglects to canonicalize the path or resolve the target of a symlink before verifying its destination. Consequently, the application interprets the symlink's resolution as a legitimate local path if the symbolic link object itself appears to be within the allowed boundary.\nThe attack flow begins when an attacker creates a malicious repository containing a symlink. This symlink is configured to point to a sensitive location outside the repository root, such as '/etc/passwd' or other configuration files containing secrets. The attacker then includes a reference to this symlink in a code block using the 'src=' attribute, which the am tool is designed to embed.\nWhen a victim executes the am command to render the documentation, the CLI processes the markdown or input files. The localPath() function validates the path to the symlink and, finding it within the expected tree, permits the operation. The application then proceeds to open the file object, which, due to standard filesystem behavior, follows the symlink to the absolute path of the sensitive file.\nThe contents of the target file are read by the application and subsequently injected into the resulting HTML output. This inclusion bypasses the intended security isolation, effectively 'leaking' the contents of the target file into the generated static site.\nThis vulnerability does not require authentication or elevated privileges beyond the ability to trigger the rendering process. The impact is primarily information disclosure; however, the severity is escalated by the potential exposure of sensitive environment variables, SSH keys, or system configuration data, which could be leveraged to perform further attacks against the victim's infrastructure or facilitate privilege escalation elsewhere."
}