Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-82007.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-82007
Upstream
Published
2026-04-08T22:16:22Z
Modified
2026-08-30T05:26:50Z
Summary
CVE-2026-40024 affecting package sleuthkit for versions less than 4.12.1-2
Details

The Sleuth Kit through 4.14.0 contains a path traversal vulnerability in tskrecover that allows an attacker to write files to arbitrary locations outside the intended recovery directory via crafted filenames or directory paths with path traversal sequences in a filesystem image. An attacker can craft a malicious filesystem image with embedded /../ sequences in filenames that, when processed by tskrecover, writes files outside the output directory, potentially achieving code execution by overwriting shell configuration or cron entries.

References

Affected packages

Azure Linux:3 / sleuthkit

Package

Name
sleuthkit
Purl
pkg:rpm/azure-linux/sleuthkit

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.1-2

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-82007.json"