Link following in gns3-server - #VU140704
Published: August 1, 2026
gns3-server
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper link resolution in gns3server.controller.import_project._create_symbolic_links when processing an uploaded .gns3project archive. A remote attacker can upload a specially crafted project archive containing a symlink entry to disclose sensitive information.
The issue is reachable through the project import endpoint, and the planted symlink can then be retrieved through the project export endpoint.