PT-2026-83287 · Duplicacy · Duplicacy

·

CVE-2026-82264

·

Published

2026-08-28

·

Updated

2026-08-28

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Duplicacy versions prior to 3.2.6
Description A path traversal issue exists in the restore function, which fails to validate entry paths deserialized from snapshot files. This allows attackers to create malicious snapshot entries using directory traversal sequences to write files to arbitrary locations outside the intended restore directory, provided the locations are accessible by the user performing the restoration.
Recommendations Update to a version newer than 3.2.5.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82264

Affected Products

Duplicacy