Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 19 Sep 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. Attackers can craft malicious archives with entries containing directory traversal sequences that bypass validation, enabling file write operations when users download and extract archives with AutoExtract enabled. | |
| Title | Gopeed through 2.0.0-beta.3 Arbitrary File Write via Path Traversal | |
| Weaknesses | CWE-22 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-19T22:58:12.558Z
Reserved: 2026-09-19T12:04:52.914Z
Link: CVE-2026-93992
No data.
Status : Received
Published: 2026-09-19T23:17:10.517
Modified: 2026-09-19T23:17:10.517
Link: CVE-2026-93992
No data.
OpenCVE Enrichment
Updated: 2026-09-20T01:00:13Z
