CVE-2026-56651

Severity CVSS v4.0:
LOW
Type:
CWE-59 Link Following
Publication date:
27/08/2026
Last modified:
28/08/2026

Description

Dool in versions up to 1.3.8 is vulnerable to symlink following when the "--devel" flag is used, as the application opens a log file without the "O_NOFOLLOW" flag. A local attacker can exploit this by creating a symlink at the expected log file path pointing to a sensitive file, causing dool to truncate and overwrite the target file with log data, which is especially impactful if dool is run with elevated privileges.<br /> The issue was addressed by pull request #116