PT-2026-48534 · Bit7Z · Bit7Z
CVE-2026-45380
·
Published
2026-06-10
·
Updated
2026-06-10
CVSS v3.1
3.6
Low
| Vector | AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
bit7z versions prior to 4.0.12
Description
A one-byte off-by-one error in the
SafeOutPathBuilder::restoreSymlink() function allows an attacker to create a specially crafted .7z archive. When extracted on non-Windows platforms, this can result in the creation of a symlink that escapes the intended output directory. Consequently, subsequent archive entries can be used to write arbitrary files outside the extraction directory using the permissions of the process performing the extraction.Recommendations
Update to version 4.0.12.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bit7Z