216.73.217.22

CVE-2026-43616

· Published 04/05/2026 18:16 · Modified 04/05/2026 18:16

Labels: CVE-2026-43616 2026-05-04CVE-2026-43616CWE-23[email protected]

Essential information

Published
04/05/2026 18:16
Modified
04/05/2026 18:16
Author
Creator
CVSS
6.8 MEDIUM (v3) 6.8 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Detect-It-Easy prior to 3.21 contains a path traversal vulnerability that allows attackers to write arbitrary files to the filesystem by crafting malicious archive entries with relative traversal sequences or absolute paths. Attackers can exploit insufficient path normalization during archive extraction to write files outside the intended extraction directory and achieve persistent code execution by overwriting user startup scripts.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
detect-it-easy / detect-it-easy cpe:2.3:a:detect-it-easy:detect-it-easy:<3.21:*:*:*:*:*:*:*

References