<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Tornado (&lt;= 6.5.8) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/tornado--6.5.8/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 04:20:55 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/tornado--6.5.8/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Tornado StaticFileHandler Symlink Path Traversal</title><link>https://feed.craftedsignal.io/briefs/2026-10-tornado-path-traversal/</link><pubDate>Thu, 01 Oct 2026 04:20:55 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-tornado-path-traversal/</guid><description>A path traversal vulnerability in Tornado's StaticFileHandler allows unauthenticated remote attackers to read arbitrary files via symbolic links within the static root directory.</description><content:encoded><![CDATA[<p>Tornado versions 6.5.8 and earlier contain a path traversal vulnerability in the <code>StaticFileHandler</code> component that permits unauthenticated attackers to read arbitrary files from the filesystem. The vulnerability exists because <code>get_absolute_path</code> and <code>validate_absolute_path</code> utilize <code>os.path.abspath()</code> to normalize requested paths and validate them against the configured static root. While <code>os.path.abspath()</code> correctly normalizes directory traversal sequences like <code>..</code>, it fails to resolve symbolic links. Subsequent file access operations (such as <code>os.path.isfile()</code>) resolve these symlinks to their actual targets.</p>
<p>If an application serves a static directory containing symlinks - often introduced by build pipelines, web frameworks, or improper user-uploaded file handling - an attacker can traverse outside the intended static root by requesting a path that resolves through a symlink to sensitive files like configuration credentials, private keys, or system files. Defending organizations must ensure that <code>StaticFileHandler</code> is not used to serve directories containing untrusted or externally-linked content, or upgrade to a version incorporating <code>os.path.realpath()</code> for validation.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies a target application utilizing the <code>tornado.web.StaticFileHandler</code>.</li>
<li>Attacker confirms the existence of a symbolic link within the application's static directory pointing to a sensitive file (e.g., <code>/etc/passwd</code> or <code>/app/config.json</code>).</li>
<li>Attacker sends a GET request to the Tornado server targeting the identified symlink (e.g., <code>GET /static/symlink_name HTTP/1.1</code>).</li>
<li>The <code>StaticFileHandler</code> invokes <code>validate_absolute_path</code>, which uses <code>os.path.abspath()</code> to check if the path starts with the configured static root.</li>
<li><code>os.path.abspath()</code> considers the path valid because it resides within the static directory structure as a string, ignoring that it is a symlink.</li>
<li>The application proceeds to the file access stage where <code>os.path.isfile()</code> and subsequent read operations resolve the symlink target.</li>
<li>The server reads the file content from the target location and returns the sensitive data to the attacker in the HTTP response body.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated remote attackers to read any file readable by the user account running the Tornado application process. Depending on the environment, this typically includes application configuration secrets, database connection strings, TLS private keys, SSH keys, source code, and sensitive system files like <code>/etc/shadow</code>. This vulnerability impacts any deployment where the static root contains symlinks, which is a common scenario in modern development environments using Docker volume mounts, webpack-based build tools, or <code>npm link</code>.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade Tornado to a version that implements <code>os.path.realpath()</code> for directory validation to resolve and restrict symlinks to the static root.</li>
<li>Identify and audit all directories served by <code>StaticFileHandler</code> for the presence of symbolic links using <code>find /path/to/static -type l</code>.</li>
<li>Implement file system permissions that restrict the Tornado process user from accessing sensitive files outside of its intended scope as a defense-in-depth measure.</li>
<li>Monitor web server logs for suspicious requests to files typically not served as static assets, such as files ending in <code>.conf</code>, <code>.key</code>, <code>.pem</code>, or system configuration files.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>path-traversal</category><category>web-application</category><category>python</category><category>tornado</category></item></channel></rss>