CVE-2026-43616

Source
https://cve.org/CVERecord?id=CVE-2026-43616
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43616.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-43616
Published
2026-05-04T17:33:48.591Z
Modified
2026-08-12T10:15:55.690115Z
Severity
  • 6.8 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Detect-It-Easy < 3.21 Path Traversal Arbitrary File Write
Details

Detect-It-Easy prior to 3.21 contains a path traversal vulnerability that allows attackers to write arbitrary files to the filesystem by crafting malicious archive entries with relative traversal sequences or absolute paths. Attackers can exploit insufficient path normalization during archive extraction to write files outside the intended extraction directory and achieve persistent code execution by overwriting user startup scripts.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43616.json",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "fixed": "3.21.0"
                }
            ]
        },
        {
            "source": "CPE_FIELD",
            "extracted_events": [
                {
                    "fixed": "3.21.0"
                }
            ]
        }
    ],
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-23"
    ]
}
References

Affected packages

Git
github.com/horsicq/die-engine

Affected ranges

Type
GIT
Repo
https://github.com/horsicq/die-engine
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

1.*
1.01
2.*
2.00
2.01
2.02
2.03
2.04
2.05
3.*
3.00
3.01
3.01b
3.02
3.03
3.03b
3.04
3.05
3.06
3.07
3.08
3.09
3.10
3.20
Other
Beta

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43616.json"
github.com/horsicq/formats

Affected ranges

Type
GIT
Repo
https://github.com/horsicq/formats
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Database specific

vanir_signatures
[
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "115832274266009691278204416960332108983",
                "242036263272246460421537467435762369906",
                "302692407514872189285489158951153408467",
                "45072213028282883822165360950487867751",
                "328040778799905045002887275676737462480",
                "39178716061759539461757923907386645958",
                "15070816031969118466734215981850099106"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-43616-f835bd65",
        "target": {
            "file": "xformats.cpp"
        },
        "source": "https://github.com/horsicq/formats/commit/56cdf50ee3c72c56284e2819b23e98332842d259",
        "signature_version": "v1"
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43616.json"
vanir_signatures_modified
"2026-08-12T10:15:55Z"
github.com/horsicq/xarchive

Affected ranges

Type
GIT
Repo
https://github.com/horsicq/xarchive
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Database specific

vanir_signatures
[
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 744.0,
            "function_hash": "313074256630960480805287768115222435137"
        },
        "id": "CVE-2026-43616-64dd7c02",
        "target": {
            "function": "XArchive::unpackCurrent",
            "file": "xarchive.cpp"
        },
        "source": "https://github.com/horsicq/xarchive/commit/6a2aa84c2fd120b704f76bb5c5ee3e9b5a7a0fcc",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 653.0,
            "function_hash": "238654648036395545538823807762972316334"
        },
        "id": "CVE-2026-43616-86d0007c",
        "target": {
            "function": "XArchives::decompressToFolder",
            "file": "xarchives.cpp"
        },
        "source": "https://github.com/horsicq/xarchive/commit/6a2aa84c2fd120b704f76bb5c5ee3e9b5a7a0fcc",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 148.0,
            "function_hash": "89961473140883943331411907334535039143"
        },
        "id": "CVE-2026-43616-a76c8128",
        "target": {
            "function": "XArchive::createInstance",
            "file": "xarchive.cpp"
        },
        "source": "https://github.com/horsicq/xarchive/commit/6a2aa84c2fd120b704f76bb5c5ee3e9b5a7a0fcc",
        "signature_version": "v1"
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "174494232420935639269315369058765583411",
                "206000467015032618223765675357612177496",
                "243118015321032809562339487489355835918",
                "246277649159689146112311028002478942117",
                "148343136086228761135447914077753709621",
                "330104500519271688350480208171951712805"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-43616-ae2be5a7",
        "target": {
            "file": "xarchives.cpp"
        },
        "source": "https://github.com/horsicq/xarchive/commit/6a2aa84c2fd120b704f76bb5c5ee3e9b5a7a0fcc",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 70.0,
            "function_hash": "20739720960040099707305032603445013173"
        },
        "id": "CVE-2026-43616-c6a5abf5",
        "target": {
            "function": "XArchive::getSearchSignatures",
            "file": "xarchive.cpp"
        },
        "source": "https://github.com/horsicq/xarchive/commit/6a2aa84c2fd120b704f76bb5c5ee3e9b5a7a0fcc",
        "signature_version": "v1"
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "311603675281675458020086045631006348905",
                "20206858867933803803819082627597269810",
                "279473527665506502488841614497306473956",
                "224469192878202927807055408940412330253",
                "53462507638433303345158931087750966817",
                "159511160457557185199845084990515260441",
                "244741757105699656011018637678026810581",
                "138046228782153642635348708299515087080",
                "150769240704769763014367631415465808244",
                "333625798657689613545999056677839568915",
                "196486139879578683352441866126734009109",
                "67697240312955517645856728190145151086",
                "194671022704353522352925692001644707872",
                "39784035394049190130840832076427500857",
                "315647326490069671116700269017979068156",
                "255104280499813751791864056382954286261",
                "115422958217687812880191223489830133791",
                "9468715492394458400492374835685347351",
                "53066593441126601790052166611770774934",
                "206466377943235791213482827812254738627",
                "242772228517697140499568438558727223189",
                "132973435797369757774048583458844998302",
                "30782873030907850440599970210271634490",
                "280319090487954553525558006634667871247",
                "25221398953477883946071053343003617794",
                "234035373975345325209823024504321088420",
                "312202502942048158891504209263974476402",
                "146079265351114528825722374518087038469",
                "185415868238709014188565328013855501653",
                "207807344786254821213472992606983140866",
                "264126712327134309109389835259632374462",
                "291932016592696410096561113883698631289",
                "277512520633384723821202764082142176805",
                "169638336873034007754753134076815219945",
                "81583980342962803435270583454082092790",
                "284612551039558522568777820820930564858",
                "49872357114778658701631759703456661732"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-43616-dd0067b1",
        "target": {
            "file": "xarchive.cpp"
        },
        "source": "https://github.com/horsicq/xarchive/commit/6a2aa84c2fd120b704f76bb5c5ee3e9b5a7a0fcc",
        "signature_version": "v1"
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43616.json"
vanir_signatures_modified
"2026-08-12T10:15:55Z"