Directory Traversal Vulnerability in Malcolm Network Traffic Analysis Tool
CVE-2026-63134
5.4MEDIUM
What is CVE-2026-63134?
Malcolm, a network traffic analysis tool, contains a vulnerability in its file extraction process prior to version 26.07.0. The issue arises from the improper handling of directory entries due to a lack of traversal protection in the safe-extract.py script. This flaw allows an attacker to upload a malicious archive containing directory entries with ../ sequences or absolute paths, leading to the unintentional creation of directories outside of the designated extraction path. This can compromise the intended security model of the application. The vulnerability is addressed in version 26.07.0, which ensures that directory entries are processed securely.
Affected Version(s)
Malcolm < 26.07.0
