Path Traversal Vulnerability in Gopeed Affected by Malicious Archive Extracts
CVE-2026-93992
7HIGH
What is CVE-2026-93992?
The Gopeed application, specifically version 2.0.0-beta.3, is susceptible to a path traversal vulnerability that occurs during archive extraction. This flaw allows malicious actors to craft specially designed archives containing directory traversal sequences. When an archive is downloaded and AutoExtract is enabled, this vulnerability can be exploited, facilitating the unauthorized writing of files outside the designated extraction directory. As a result, the security of the affected systems and data integrity may be severely compromised if adequate precautions are not taken.
Affected Version(s)
gopeed 0 <= 2.0.0-beta.3
