{"id":"CVE-2026-77113","summary":"Path Traversal Vulnerability in apport-unpack","details":"Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary files with the privileges of the executing user via an attacker controlled key names in crash report files.","modified":"2026-08-30T03:30:36.943615391Z","published":"2026-08-20T22:32:51.447Z","database_specific":{"cna_assigner":"canonical","cwe_ids":["CWE-23"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77113.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77113.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77113"},{"type":"REPORT","url":"https://launchpad.net/bugs/2161697"},{"type":"FIX","url":"https://github.com/canonical/apport/pull/646"},{"type":"PACKAGE","url":"https://github.com/canonical/apport"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/canonical/apport","events":[{"introduced":"0"},{"fixed":"d7b9734ba58330d551bac2468752116f732cb0a2"},{"fixed":"870d0ffcbbdb75c58d1dff9637320e79f646c7f0"},{"fixed":"b7c23adb21c4d37a433d948ba9a6e61654add3b1"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.36.0"},{"fixed":"2.34.2"},{"fixed":"2.28.4"}],"source":"AFFECTED_FIELD"}}],"versions":["2.28.3","2.35.0","2.34.1","2.28.2","2.34.0","2.28.1","2.33.1","2.33.0","2.32.0","2.31.0","2.30.0","2.29.0","2.28.0","2.27.0","2.26.1","2.26.0","2.25.0","2.24.0","2.23.1","2.23.0","2.22.0","2.21.0","2.20.11","2.20.10","2.20.9","2.20.8","2.20.7","2.20.6","2.20.5","2.20.4","2.20.3","2.20.2","2.20.1","2.20","2.19.4","2.19.3","2.19.2","2.19.1","2.19","2.18.1","2.18","2.17.3","2.17.2","2.17.1","2.17","2.16.2","2.16.1","2.16","2.15.1","2.15","2.14.7","2.14.6","2.14.5","2.14.4","2.14.3","2.14.2","2.14.1","2.14","2.13.3","2.13.2","2.12.7","2.13.1","2.13","2.12.6","2.12.5","2.12.4","2.12.3","2.12.2","2.12.1","2.12","2.11","2.10.2","2.10.1","2.10","2.9.2","2.9.1","2.9","2.8","2.7","2.6.3","2.6.2","2.6.1","2.6","2.5.3","2.5.2","2.5.1","2.5","2.4","2.3","2.2.5","2.2.4","2.2.3","2.2.2","2.2.1","2.2","2.1.1","2.1","2.0.1","2.0","1.95","1.94.1","1.94","1.93","1.92","1.91","1.90","1.26","1.25","1.24","1.23.1","1.23","1.22.1","1.22","1.21.3","1.21.2","1.21.1","1.21","1.20.1","1.20","1.19","1.18","1.17.2","1.17.1","1.17","1.16","1.15","1.14.1","1.14","1.13.4","1.13.3","1.13.2","1.13.1","1.13","1.12.1","1.12","1.11","1.10.1","1.10","1.9.6","1.9.5","1.9.4","1.9.3","1.9.2","1.9.1","1.9","1.8.2","1.8.1","1.8","1.7","1.6","1.5","1.4","1.3","1.2.1","1.2.0","1.1.1","1.1","0.149","1.0","0.148","0.147","0.146","0.145","0.144","0.143","0.142","0.141","0.140","0.139","0.138","0.136","0.135","0.134","0.133","0.132","0.131","0.130","0.129","0.128","0.127","0.126","0.125","0.121","0.124","0.123","0.122","0.120","0.119","0.117","0.116","0.115","0.114","0.112","0.111"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-77113.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}