PT-2026-62011 · Malcolm · Malcolm
CVE-2026-63134
·
Published
2026-07-21
·
Updated
2026-08-11
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Malcolm versions prior to 26.07.0
Description
The
safe-extract.py script fails to implement traversal protection when creating directory entries using the os.makedirs(os.path.join(dest, entry.pathname)) function. An attacker can upload a malicious archive containing an absolute path or a ../ sequence in a directory entry, which allows the filebeat processing container to create directories outside of the intended extraction path. Path traversal is a technique used to access files or directories that are outside the intended folder by using special characters like ../ to move up the directory hierarchy.Recommendations
Update to version 26.07.0.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Malcolm