Path Traversal Vulnerability in Gopeed Affected by Malicious Archive Extracts
CVE-2026-93992

7HIGH

Key Information:

Vendor

Gopeedlab

Status
Vendor
CVE Published:
19 September 2026

What is CVE-2026-93992?

The Gopeed application, specifically version 2.0.0-beta.3, is susceptible to a path traversal vulnerability that occurs during archive extraction. This flaw allows malicious actors to craft specially designed archives containing directory traversal sequences. When an archive is downloaded and AutoExtract is enabled, this vulnerability can be exploited, facilitating the unauthorized writing of files outside the designated extraction directory. As a result, the security of the affected systems and data integrity may be severely compromised if adequate precautions are not taken.

Affected Version(s)

gopeed 0 <= 2.0.0-beta.3

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yu Sun
.