PT-2026-48534 · Bit7Z · Bit7Z

CVE-2026-45380

·

Published

2026-06-10

·

Updated

2026-06-10

CVSS v3.1

3.6

Low

VectorAV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions bit7z versions prior to 4.0.12
Description A one-byte off-by-one error in the SafeOutPathBuilder::restoreSymlink() function allows an attacker to create a specially crafted .7z archive. When extracted on non-Windows platforms, this can result in the creation of a symlink that escapes the intended output directory. Consequently, subsequent archive entries can be used to write arbitrary files outside the extraction directory using the permissions of the process performing the extraction.
Recommendations Update to version 4.0.12.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45380
GHSA-8WJ8-9JWV-J24V

Affected Products

Bit7Z