PT-2026-95876 · Gopeed · Gopeed
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Gopeed versions prior to 2.0.0-beta.4
Description
A path traversal issue exists during archive extraction, allowing attackers to write arbitrary files outside the intended extraction directory. This occurs when users download and extract archives with the AutoExtract feature enabled. Attackers can achieve this by crafting malicious archives containing directory traversal sequences that bypass validation.
Recommendations
Update Gopeed to version 2.0.0-beta.4 or later.
Disable the AutoExtract feature as a temporary mitigation measure.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gopeed