CVE-2015-7314: Gollum Project Gollum
Medium severity, CVSS 4.3. EPSS: 1.9% chance of exploitation in the next 30 days.
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check.
Affected products
- Gollum Project Gollum: up to and including 4.0
Published 2015-10-06. Last modified 2026-06-17.