PT-2026-83287 · Duplicacy · Duplicacy
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Duplicacy versions prior to 3.2.6
Description
A path traversal issue exists in the restore function, which fails to validate entry paths deserialized from snapshot files. This allows attackers to create malicious snapshot entries using directory traversal sequences to write files to arbitrary locations outside the intended restore directory, provided the locations are accessible by the user performing the restoration.
Recommendations
Update to a version newer than 3.2.5.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Duplicacy