CVE-2026-40491
MEDIUMgdown Affected by Arbitrary File Write via Path Traversal in gdown.extractall
Title source: cnaDescription
gdown is a Google Drive public file/folder downloader. Versions prior to 5.2.2 are vulnerable to a Path Traversal attack within the extractall functionality. When extracting a maliciously crafted ZIP or TAR archive, the library fails to sanitize or validate the filenames of the archive members. This allow files to be written outside the intended destination directory, potentially leading to arbitrary file overwrite and Remote Code Execution (RCE). Version 5.2.2 contains a fix.
References (3)
Scores
CVSS v3
6.5
EPSS
0.0005
EPSS Percentile
14.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Details
CWE
CWE-22
Status
published
Products (1)
wkentaro/gdown
< 5.2.2
Published
Apr 18, 2026
Tracked Since
Apr 18, 2026