CVE-2015-7314: Gollum Project Gollum

Medium severity, CVSS 4.3. EPSS: 1.9% chance of exploitation in the next 30 days.

The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check.

Affected products

Published 2015-10-06. Last modified 2026-06-17.