CVE-2026-43616

HIGH

Detect-It-Easy < 3.21 Path Traversal Arbitrary File Write

Title source: cna
STIX 2.1

Description

Detect-It-Easy prior to 3.21 contains a path traversal vulnerability that allows attackers to write arbitrary files to the filesystem by crafting malicious archive entries with relative traversal sequences or absolute paths. Attackers can exploit insufficient path normalization during archive extraction to write files outside the intended extraction directory and achieve persistent code execution by overwriting user startup scripts.

Scores

CVSS v3 7.1
EPSS 0.0002
EPSS Percentile 4.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-23
Status published
Products (1)
horsicq/DIE-engine < 3.21.0
Published May 04, 2026
Tracked Since May 04, 2026