Medium severity6.8NVD Advisory· Published Aug 28, 2026
CVE-2026-82264
CVE-2026-82264
Description
Duplicacy through 3.2.5 contains a path traversal vulnerability in the restore function that fails to validate entry paths deserialized from snapshot files. Attackers can craft malicious snapshot entries with directory traversal sequences to write files outside the restore directory to arbitrary locations accessible by the restoring user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3(expand)+ 1 more
- (no CPE)
- (no CPE)range: <=3.2.5
Patches
Vulnerability mechanics
References
4- github.com/gilbertchen/duplicacy/blob/54f97522bff9df8be6797873203310ccbf5a5b00/src/duplicacy_backupmanager.gonvd
- github.com/gilbertchen/duplicacy/blob/54f97522bff9df8be6797873203310ccbf5a5b00/src/duplicacy_utils_others.gonvd
- github.com/gilbertchen/duplicacy/issues/692nvd
- www.vulncheck.com/advisories/duplicacy-path-traversal-during-restore-via-unsanitized-snapshot-pathsnvd
News mentions
0No linked articles in our index yet.