PT-2026-62011 · Malcolm · Malcolm

CVE-2026-63134

·

Published

2026-07-21

·

Updated

2026-08-11

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Malcolm versions prior to 26.07.0
Description The safe-extract.py script fails to implement traversal protection when creating directory entries using the os.makedirs(os.path.join(dest, entry.pathname)) function. An attacker can upload a malicious archive containing an absolute path or a ../ sequence in a directory entry, which allows the filebeat processing container to create directories outside of the intended extraction path. Path traversal is a technique used to access files or directories that are outside the intended folder by using special characters like ../ to move up the directory hierarchy.
Recommendations Update to version 26.07.0.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63134
GHSA-65MM-VGRW-VQX4

Affected Products

Malcolm