VYPR

Evil-WinRM

by Hackplayers

CVEs (1)

  • CVE-2026-55201Jun 17, 2026
    risk 0.00cvss epss

    Evil-WinRM through 3.9, fixed in commit 6ecd570, contains a path traversal vulnerability in the download_dir() function that allows a rogue or compromised remote Windows server to write files outside the intended download directory by returning filenames with traversal sequences…