Directory Traversal Vulnerability in Malcolm Network Traffic Analysis Tool
CVE-2026-63134

5.4MEDIUM

Key Information:

Vendor

Cisagov

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-63134?

Malcolm, a network traffic analysis tool, contains a vulnerability in its file extraction process prior to version 26.07.0. The issue arises from the improper handling of directory entries due to a lack of traversal protection in the safe-extract.py script. This flaw allows an attacker to upload a malicious archive containing directory entries with ../ sequences or absolute paths, leading to the unintentional creation of directories outside of the designated extraction path. This can compromise the intended security model of the application. The vulnerability is addressed in version 26.07.0, which ensures that directory entries are processed securely.

Affected Version(s)

Malcolm < 26.07.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.