{"id":"CVE-2026-43616","summary":"Detect-It-Easy \u003c 3.21 Path Traversal Arbitrary File Write","details":"Detect-It-Easy prior to 3.21 contains a path traversal vulnerability that allows attackers to write arbitrary files to the filesystem by crafting malicious archive entries with relative traversal sequences or absolute paths. Attackers can exploit insufficient path normalization during archive extraction to write files outside the intended extraction directory and achieve persistent code execution by overwriting user startup scripts.","modified":"2026-08-12T10:15:55.690115Z","published":"2026-05-04T17:33:48.591Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-23"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43616.json","unresolved_ranges":[{"extracted_events":[{"fixed":"3.21.0"}],"source":"AFFECTED_FIELD"},{"extracted_events":[{"fixed":"3.21.0"}],"source":"CPE_FIELD"}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43616.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-43616"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/detect-it-easy-path-traversal-arbitrary-file-write"},{"type":"FIX","url":"https://github.com/horsicq/DIE-engine/commit/7fd300b926daf19707b2a36f0abe8b60a51308ee"},{"type":"FIX","url":"https://github.com/horsicq/DIE-engine/commit/cbbe1688e58ffd430d284bf65f336973f083db69"},{"type":"FIX","url":"https://github.com/horsicq/DIE-engine/releases/tag/3.21"},{"type":"FIX","url":"https://github.com/horsicq/Formats/commit/56cdf50ee3c72c56284e2819b23e98332842d259"},{"type":"FIX","url":"https://github.com/horsicq/XArchive/commit/6a2aa84c2fd120b704f76bb5c5ee3e9b5a7a0fcc"},{"type":"PACKAGE","url":"https://github.com/horsicq/Detect-It-Easy"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/horsicq/die-engine","events":[{"introduced":"0"},{"fixed":"7fd300b926daf19707b2a36f0abe8b60a51308ee"},{"fixed":"cbbe1688e58ffd430d284bf65f336973f083db69"},{"fixed":"72947a0c71dc741165411d63c01bfca79809513e"}],"database_specific":{"source":"REFERENCES"}}],"versions":["3.20","Beta","3.10","3.09","3.08","3.07","3.06","3.05","3.04","3.03","3.03b","3.02","3.01","3.01b","3.00","2.05","2.04","2.03","2.02","2.01","2.00","1.01"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43616.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/horsicq/formats","events":[{"introduced":"0"},{"fixed":"56cdf50ee3c72c56284e2819b23e98332842d259"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43616.json","vanir_signatures_modified":"2026-08-12T10:15:55Z","vanir_signatures":[{"digest":{"threshold":0.9,"line_hashes":["115832274266009691278204416960332108983","242036263272246460421537467435762369906","302692407514872189285489158951153408467","45072213028282883822165360950487867751","328040778799905045002887275676737462480","39178716061759539461757923907386645958","15070816031969118466734215981850099106"]},"id":"CVE-2026-43616-f835bd65","signature_type":"Line","signature_version":"v1","source":"https://github.com/horsicq/formats/commit/56cdf50ee3c72c56284e2819b23e98332842d259","target":{"file":"xformats.cpp"},"deprecated":false}]}},{"ranges":[{"type":"GIT","repo":"https://github.com/horsicq/xarchive","events":[{"introduced":"0"},{"fixed":"6a2aa84c2fd120b704f76bb5c5ee3e9b5a7a0fcc"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43616.json","vanir_signatures_modified":"2026-08-12T10:15:55Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/horsicq/xarchive/commit/6a2aa84c2fd120b704f76bb5c5ee3e9b5a7a0fcc","target":{"file":"xarchive.cpp","function":"XArchive::unpackCurrent"},"deprecated":false,"digest":{"function_hash":"313074256630960480805287768115222435137","length":744},"id":"CVE-2026-43616-64dd7c02","signature_type":"Function"},{"target":{"file":"xarchives.cpp","function":"XArchives::decompressToFolder"},"deprecated":false,"digest":{"length":653,"function_hash":"238654648036395545538823807762972316334"},"id":"CVE-2026-43616-86d0007c","signature_type":"Function","signature_version":"v1","source":"https://github.com/horsicq/xarchive/commit/6a2aa84c2fd120b704f76bb5c5ee3e9b5a7a0fcc"},{"id":"CVE-2026-43616-a76c8128","signature_type":"Function","signature_version":"v1","source":"https://github.com/horsicq/xarchive/commit/6a2aa84c2fd120b704f76bb5c5ee3e9b5a7a0fcc","target":{"file":"xarchive.cpp","function":"XArchive::createInstance"},"deprecated":false,"digest":{"function_hash":"89961473140883943331411907334535039143","length":148}},{"signature_version":"v1","source":"https://github.com/horsicq/xarchive/commit/6a2aa84c2fd120b704f76bb5c5ee3e9b5a7a0fcc","target":{"file":"xarchives.cpp"},"deprecated":false,"digest":{"line_hashes":["174494232420935639269315369058765583411","206000467015032618223765675357612177496","243118015321032809562339487489355835918","246277649159689146112311028002478942117","148343136086228761135447914077753709621","330104500519271688350480208171951712805"],"threshold":0.9},"id":"CVE-2026-43616-ae2be5a7","signature_type":"Line"},{"signature_version":"v1","source":"https://github.com/horsicq/xarchive/commit/6a2aa84c2fd120b704f76bb5c5ee3e9b5a7a0fcc","target":{"file":"xarchive.cpp","function":"XArchive::getSearchSignatures"},"deprecated":false,"digest":{"function_hash":"20739720960040099707305032603445013173","length":70},"id":"CVE-2026-43616-c6a5abf5","signature_type":"Function"},{"id":"CVE-2026-43616-dd0067b1","signature_type":"Line","signature_version":"v1","source":"https://github.com/horsicq/xarchive/commit/6a2aa84c2fd120b704f76bb5c5ee3e9b5a7a0fcc","target":{"file":"xarchive.cpp"},"deprecated":false,"digest":{"line_hashes":["311603675281675458020086045631006348905","20206858867933803803819082627597269810","279473527665506502488841614497306473956","224469192878202927807055408940412330253","53462507638433303345158931087750966817","159511160457557185199845084990515260441","244741757105699656011018637678026810581","138046228782153642635348708299515087080","150769240704769763014367631415465808244","333625798657689613545999056677839568915","196486139879578683352441866126734009109","67697240312955517645856728190145151086","194671022704353522352925692001644707872","39784035394049190130840832076427500857","315647326490069671116700269017979068156","255104280499813751791864056382954286261","115422958217687812880191223489830133791","9468715492394458400492374835685347351","53066593441126601790052166611770774934","206466377943235791213482827812254738627","242772228517697140499568438558727223189","132973435797369757774048583458844998302","30782873030907850440599970210271634490","280319090487954553525558006634667871247","25221398953477883946071053343003617794","234035373975345325209823024504321088420","312202502942048158891504209263974476402","146079265351114528825722374518087038469","185415868238709014188565328013855501653","207807344786254821213472992606983140866","264126712327134309109389835259632374462","291932016592696410096561113883698631289","277512520633384723821202764082142176805","169638336873034007754753134076815219945","81583980342962803435270583454082092790","284612551039558522568777820820930564858","49872357114778658701631759703456661732"],"threshold":0.9}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N"}]}