Path Traversal Vulnerability in VisiData by VisiData Team
CVE-2026-41958
6.5MEDIUM
What is CVE-2026-41958?
A path traversal vulnerability has been identified in the unzip_http RemoteZipFile extract functionality of VisiData. This flaw allows an attacker to exploit specially crafted .zip files to execute arbitrary file write operations. By delivering a malicious URL, the attacker can manipulate file paths, potentially compromising system integrity and exposing sensitive data.
Affected Version(s)
visidata dev (commit 38b21f78)
