Path Traversal Vulnerability in VisiData by VisiData Inc.
CVE-2026-42532

5.5MEDIUM

Key Information:

Vendor

Visidata

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-42532?

A path traversal vulnerability exists within the EmailSheet extract_parts functionality of VisiData. This flaw enables attackers to craft a specially formatted .eml file, which can lead to arbitrary file writes on the server. By exploiting this vulnerability, an attacker can manipulate file paths to write files in unauthorized locations, potentially compromising the integrity and security of the application and the server it operates on.

Affected Version(s)

visidata dev (commit 38b21f78)

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Claudio Bozzato of Cisco Talos
.