{"id":"CVE-2021-29488","details":"SABnzbd is an open source binary newsreader. A vulnerability was discovered in SABnzbd that could trick the `filesystem.renamer()` function into writing downloaded files outside the configured Download Folder via malicious PAR2 files. A patch was released as part of SABnzbd 3.2.1RC1. As a workaround, limit downloads to NZBs without PAR2 files, deny write permissions to the SABnzbd process outside areas it must access to perform its job, or update to a fixed version.","modified":"2026-04-10T04:31:59.789907Z","published":"2021-05-07T15:15:07.503Z","related":["GHSA-jwj3-wrvf-v3rp"],"references":[{"type":"FIX","url":"https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-jwj3-wrvf-v3rp"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/sabnzbd/sabnzbd","events":[{"introduced":"0"},{"fixed":"008794089866a0fa5fd39818806d34e9d0d8098d"},{"introduced":"0"},{"fixed":"a9d86a7447ccb7ebbae37d704ccd5c0e2e1f326d"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"3.0.0"},{"introduced":"0"},{"fixed":"3.2.1"}]}}],"versions":["0.6.0","0.6.1","0.6.2","0.6.3","0.6.4","0.6.5","0.6.6","0.6.7","0.6.8","0.6.8RC1","0.7.0","0.7.0Alpha1","0.7.0Alpha2","0.7.0Alpha3","0.7.0Beta1","0.7.0Beta2","0.7.0Beta3","0.7.0Beta4","0.7.0Beta5","0.7.0Beta6","0.7.0Beta7","0.7.0Beta8","0.7.0RC1","0.7.0RC2","0.7.1","0.7.10","0.7.11","0.7.1RC1","0.7.1RC2","0.7.1RC3","0.7.1RC4","0.7.1RC5","0.7.2","0.7.2RC1","0.7.2RC2","0.7.3","0.7.3Beta1","0.7.3Beta2","0.7.3RC1","0.7.4","0.7.4Beta1","0.7.4Beta2","0.7.4Beta3","0.7.4RC1","0.7.4RC2","0.7.5","0.7.5RC1","0.7.6","0.7.6Beta1","0.7.6Beta2","0.7.6Final","0.7.7","0.7.8","0.7.8RC1","0.7.9","0.7.9RC1","2.0.0","2.0.1","2.1.0","2.2.0","2.2.1","2.3.0","2.3.1","2.3.2","2.3.3","2.3.4","2.3.5","2.3.6","2.3.7","2.3.8","2.3.9","3.0.0","3.0.1","3.0.2","3.1.0","3.1.1","3.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-29488.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}