CVE-2026-43616 PUBLISHED

Detect-It-Easy < 3.21 Path Traversal Arbitrary File Write

Assigner: VulnCheck
Reserved: 01.05.2026 Published: 04.05.2026 Updated: 04.05.2026

Detect-It-Easy prior to 3.21 contains a path traversal vulnerability that allows attackers to write arbitrary files to the filesystem by crafting malicious archive entries with relative traversal sequences or absolute paths. Attackers can exploit insufficient path normalization during archive extraction to write files outside the intended extraction directory and achieve persistent code execution by overwriting user startup scripts.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 6.8

Product Status

Vendor horsicq
Product DIE-engine
Versions Default: affected
  • affected from 0 to 3.21.0 (excl.)

Credits

  • Mobasi Security Team finder

References

Problem Types

  • CWE-23: Relative Path Traversal CWE