CVE-2026-26058

Source
https://cve.org/CVERecord?id=CVE-2026-26058
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-26058.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-26058
Aliases
  • GHSA-xm5c-c6mp-3956
Published
2026-04-03T20:59:08.941Z
Modified
2026-08-05T03:31:56.046720214Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N CVSS Calculator
Summary
Zulip: Path Traversal in Import
Details

Zulip is an open-source team collaboration tool. From version 1.4.0 to before version 11.6, ./manage.py import reads arbitrary files from the server filesystem via path traversal in uploads/records.json. A crafted export tarball causes the server to copy any file the zulip user can read into the uploads directory during import. This issue has been patched in version 11.6.

Database specific
{
    "cwe_ids": [
        "CWE-22"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26058.json",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "1.4.0"
                },
                {
                    "fixed": "11.6"
                }
            ]
        },
        {
            "source": "DESCRIPTION",
            "extracted_events": [
                {
                    "fixed": "11.6"
                }
            ]
        }
    ]
}
References

Affected packages

Git / github.com/zulip/zulip

Affected ranges

Type
GIT
Repo
https://github.com/zulip/zulip
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "REFERENCES"
}

Affected versions

1.*
1.3.0
1.3.1
1.3.10
1.3.11
1.3.13
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.5.0
1.6.0
1.7.0
1.8.0
1.8.0-rc1
1.9.0
1.9.0-rc2
1.9.0-rc3
10.*
10.0
10.0-beta1
10.0-beta2
11.*
11.0
11.0-beta1
11.0-beta2
11.0-dev
11.1
11.2
11.3
11.4
11.5
2.*
2.0.0
2.0.0-rc1
2.1-dev
2.1.0
2.1.0-rc1
2.2-dev
3.*
3.0
3.0-dev
3.0-rc1
3.0-rc2
4.*
4.0
4.0-dev
5.*
5.0
5.0-dev
6.*
6.0
6.0-dev
7.*
7.0
7.0-beta3
7.0-dev
8.*
8.0
8.0-beta1
8.0-beta2
8.0-dev
9.*
9.0
9.0-beta1
9.0-dev
enterprise-1.*
enterprise-1.1.5
enterprise-1.2.0
shared-0.*
shared-0.0.1
shared-0.0.10
shared-0.0.11
shared-0.0.12
shared-0.0.13
shared-0.0.14
shared-0.0.15
shared-0.0.16
shared-0.0.17
shared-0.0.18
shared-0.0.2
shared-0.0.3
shared-0.0.4
shared-0.0.5
shared-0.0.6
shared-0.0.7
shared-0.0.8
shared-0.0.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-26058.json"

Git / github.com/zulip/zulip-mobile

Affected ranges

Type
GIT
Repo
https://github.com/zulip/zulip-mobile
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "source": "CPE_RANGE",
    "cpe": "cpe:2.3:a:zulip:zulip:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.4.0"
        },
        {
            "last_affected": "11.5"
        }
    ]
}

Affected versions

0.*
0.7.1
1.*
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.17
1.0.18
1.0.19
1.0.20
1.0.21
1.0.22
1.0.24
1.0.25
1.0.26
1.0.27
1.0.29
10.*
10.1.70
11.*
11.1.73
11.3.74
11.4.75
11.5.76
2.*
2.1.33
2.3.35
2.7.39
3.*
3.0.40
3.1.41
3.2.42
3.3.43
5.*
5.0.46
6.*
6.6.53
7.*
7.0.54
7.1.55
7.3.57
8.*
8.1.62
8.2.63
8.3.64
9.*
9.1.67

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-26058.json"