Critical Path Traversal Vulnerability in GopeedLab Affects Archive Extraction
Article Content
- •CVE-2026-93992 allows arbitrary file writes outside extraction directories.
- •Affected systems include Gopeed version 2.0.0-beta.3 with AutoExtract enabled.
- •Immediate action is required to mitigate the risk of exploitation.
GopeedLab's Gopeed version 2.0.0-beta.3 contains a critical path traversal vulnerability (CVE-2026-93992) that allows attackers to write arbitrary files outside the intended extraction directory. This vulnerability is due to improper sanitization of file paths in the archive extraction process, specifically when using AutoExtract. Attackers can exploit this by crafting malicious archives that contain directory traversal sequences, potentially overwriting sensitive files or executing arbitrary code. The vulnerability affects all formats routed through the extraction handler, including 7z, zip, tar, and rar. Users with AutoExtract enabled are particularly at risk, especially on managed endpoints and shared systems. The severity of this vulnerability is classified as critical, requiring immediate remediation. Active exploitation has not been confirmed, but the risk remains high due to the ease of exploitation. Users are advised to disable AutoExtract and upgrade to the fixed release as soon as possible.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-93992 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…