Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.0

CVE-2026-93992: Gopeed can write files outside intended folder via malicious archive

CVE-2026-93992 · published 9 days ago
Summary

Gopeed up to version 2.0.0-beta.3 may place files anywhere on the system when a user downloads a crafted archive and has the AutoExtract feature turned on. This lets an attacker add or overwrite files outside the normal extraction folder, potentially compromising the computer. Turn off AutoExtract or update to a version where the issue is fixed.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
gopeedlab gopeed <= 2.0.0-beta.3
Original advisory text
Gopeed through 2.0.0-beta.3 Arbitrary File Write via Path Traversal
Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. Attackers can craft malicious archives with entries containing directory traversal sequences that bypass validation, enabling file write operations when users download and extract archives with AutoExtract enabled.
Severity
7.0 High
CVSS 3.1: 8.1 (MITRE)
Exploitation
EPSS <1%
Type
CWE-22Path Traversal
Timeline
Published19 Sep 2026
Updated29 Sep 2026
First seen19 Sep 2026
Sources
CVE-2026-93992 · MITRE
Track software like this
Free during beta