Skip to content
Critical Path Traversal Vulnerability in GopeedLab Affects Archive Extraction

Critical Path Traversal Vulnerability in GopeedLab Affects Archive Extraction

First seen 20 Sep 2026, 00:23 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 20, 2026 at 00:24 UTC
  • CVE-2026-93992 allows arbitrary file writes outside extraction directories.
  • Affected systems include Gopeed version 2.0.0-beta.3 with AutoExtract enabled.
  • Immediate action is required to mitigate the risk of exploitation.

GopeedLab's Gopeed version 2.0.0-beta.3 contains a critical path traversal vulnerability (CVE-2026-93992) that allows attackers to write arbitrary files outside the intended extraction directory. This vulnerability is due to improper sanitization of file paths in the archive extraction process, specifically when using AutoExtract. Attackers can exploit this by crafting malicious archives that contain directory traversal sequences, potentially overwriting sensitive files or executing arbitrary code. The vulnerability affects all formats routed through the extraction handler, including 7z, zip, tar, and rar. Users with AutoExtract enabled are particularly at risk, especially on managed endpoints and shared systems. The severity of this vulnerability is classified as critical, requiring immediate remediation. Active exploitation has not been confirmed, but the risk remains high due to the ease of exploitation. Users are advised to disable AutoExtract and upgrade to the fixed release as soon as possible.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-19
CVE-2026-93992 published
GopeedLab disclosed a critical path traversal vulnerability affecting archive extraction in Gopeed.
Redpacketsecurity
2026-09-20
GitHub issue reported
Gopeed's archive extraction was found to have three independent zip-slip vectors, leading to arbitrary file writes.
github.com

More articles in this cluster (2)

Following this threat?

Track CVE-2026-93992 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed