Path Traversal Vulnerability in Cryptomator by Cryptomator
CVE-2026-32310

4.1MEDIUM

Key Information:

Vendor
CVE Published:
20 March 2026

What is CVE-2026-32310?

The vulnerability in Cryptomator arises from improper handling of vault configurations, allowing attackers to exploit unverified paths. When an attacker provides a malicious vault configuration, they can manipulate the masterkeyfile loader to access unauthorized file system locations. This is particularly harmful on Windows systems, where attackers can leverage UNC paths to trigger outbound SMB access, potentially exposing sensitive data before users authenticate. This flaw has been addressed in version 1.19.1.

Affected Version(s)

cryptomator >= 1.6.0, <= 1.19.0

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.