Detect-It-Easy prior to 3.21 contains a path traversal vulnerability that allows attackers to write arbitrary files to the filesystem by crafting malicious archive entries with relative traversal sequences or absolute paths. Attackers can exploit insufficient path normalization during archive extraction to write files outside the intended extraction directory and achieve persistent code execution by overwriting user startup scripts.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 04 May 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Detect-It-Easy prior to 3.21 contains a path traversal vulnerability that allows attackers to write arbitrary files to the filesystem by crafting malicious archive entries with relative traversal sequences or absolute paths. Attackers can exploit insufficient path normalization during archive extraction to write files outside the intended extraction directory and achieve persistent code execution by overwriting user startup scripts. | |
| Title | Detect-It-Easy < 3.21 Path Traversal Arbitrary File Write | |
| Weaknesses | CWE-23 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-04T17:33:48.591Z
Reserved: 2026-05-01T18:22:45.639Z
Link: CVE-2026-43616
No data.
Status : Received
Published: 2026-05-04T18:16:32.830
Modified: 2026-05-04T18:16:32.830
Link: CVE-2026-43616
No data.
OpenCVE Enrichment
Updated: 2026-05-04T18:30:06Z
Weaknesses