High severity7.1NVD Advisory· Published May 4, 2026· Updated May 29, 2026
CVE-2026-43616
CVE-2026-43616
Description
Detect-It-Easy prior to 3.21 contains a path traversal vulnerability that allows attackers to write arbitrary files to the filesystem by crafting malicious archive entries with relative traversal sequences or absolute paths. Attackers can exploit insufficient path normalization during archive extraction to write files outside the intended extraction directory and achieve persistent code execution by overwriting user startup scripts.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <3.21
Patches
Vulnerability mechanics
References
6- github.com/horsicq/DIE-engine/commit/7fd300b926daf19707b2a36f0abe8b60a51308eenvdPatch
- github.com/horsicq/DIE-engine/commit/cbbe1688e58ffd430d284bf65f336973f083db69nvdPatch
- github.com/horsicq/Formats/commit/56cdf50ee3c72c56284e2819b23e98332842d259nvdPatch
- github.com/horsicq/XArchive/commit/6a2aa84c2fd120b704f76bb5c5ee3e9b5a7a0fccnvdPatch
- www.vulncheck.com/advisories/detect-it-easy-path-traversal-arbitrary-file-writenvdThird Party Advisory
- github.com/horsicq/DIE-engine/releases/tag/3.21nvdRelease Notes
News mentions
0No linked articles in our index yet.