Detect-It-Easy prior to 3.21 contains a path traversal vulnerability that allows attackers to write arbitrary files to the filesystem by crafting malicious archive entries with relative traversal sequences or absolute paths. Attackers can exploit insufficient path normalization during archive extraction to write files outside the intended extraction directory and achieve persistent code execution by overwriting user startup scripts.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43616.json",
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"fixed": "3.21.0"
}
]
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "3.21.0"
}
]
}
],
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-23"
]
}[
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"115832274266009691278204416960332108983",
"242036263272246460421537467435762369906",
"302692407514872189285489158951153408467",
"45072213028282883822165360950487867751",
"328040778799905045002887275676737462480",
"39178716061759539461757923907386645958",
"15070816031969118466734215981850099106"
],
"threshold": 0.9
},
"id": "CVE-2026-43616-f835bd65",
"target": {
"file": "xformats.cpp"
},
"source": "https://github.com/horsicq/formats/commit/56cdf50ee3c72c56284e2819b23e98332842d259",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43616.json"
"2026-08-12T10:15:55Z"
[
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 744.0,
"function_hash": "313074256630960480805287768115222435137"
},
"id": "CVE-2026-43616-64dd7c02",
"target": {
"function": "XArchive::unpackCurrent",
"file": "xarchive.cpp"
},
"source": "https://github.com/horsicq/xarchive/commit/6a2aa84c2fd120b704f76bb5c5ee3e9b5a7a0fcc",
"signature_version": "v1"
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 653.0,
"function_hash": "238654648036395545538823807762972316334"
},
"id": "CVE-2026-43616-86d0007c",
"target": {
"function": "XArchives::decompressToFolder",
"file": "xarchives.cpp"
},
"source": "https://github.com/horsicq/xarchive/commit/6a2aa84c2fd120b704f76bb5c5ee3e9b5a7a0fcc",
"signature_version": "v1"
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 148.0,
"function_hash": "89961473140883943331411907334535039143"
},
"id": "CVE-2026-43616-a76c8128",
"target": {
"function": "XArchive::createInstance",
"file": "xarchive.cpp"
},
"source": "https://github.com/horsicq/xarchive/commit/6a2aa84c2fd120b704f76bb5c5ee3e9b5a7a0fcc",
"signature_version": "v1"
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"174494232420935639269315369058765583411",
"206000467015032618223765675357612177496",
"243118015321032809562339487489355835918",
"246277649159689146112311028002478942117",
"148343136086228761135447914077753709621",
"330104500519271688350480208171951712805"
],
"threshold": 0.9
},
"id": "CVE-2026-43616-ae2be5a7",
"target": {
"file": "xarchives.cpp"
},
"source": "https://github.com/horsicq/xarchive/commit/6a2aa84c2fd120b704f76bb5c5ee3e9b5a7a0fcc",
"signature_version": "v1"
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 70.0,
"function_hash": "20739720960040099707305032603445013173"
},
"id": "CVE-2026-43616-c6a5abf5",
"target": {
"function": "XArchive::getSearchSignatures",
"file": "xarchive.cpp"
},
"source": "https://github.com/horsicq/xarchive/commit/6a2aa84c2fd120b704f76bb5c5ee3e9b5a7a0fcc",
"signature_version": "v1"
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"311603675281675458020086045631006348905",
"20206858867933803803819082627597269810",
"279473527665506502488841614497306473956",
"224469192878202927807055408940412330253",
"53462507638433303345158931087750966817",
"159511160457557185199845084990515260441",
"244741757105699656011018637678026810581",
"138046228782153642635348708299515087080",
"150769240704769763014367631415465808244",
"333625798657689613545999056677839568915",
"196486139879578683352441866126734009109",
"67697240312955517645856728190145151086",
"194671022704353522352925692001644707872",
"39784035394049190130840832076427500857",
"315647326490069671116700269017979068156",
"255104280499813751791864056382954286261",
"115422958217687812880191223489830133791",
"9468715492394458400492374835685347351",
"53066593441126601790052166611770774934",
"206466377943235791213482827812254738627",
"242772228517697140499568438558727223189",
"132973435797369757774048583458844998302",
"30782873030907850440599970210271634490",
"280319090487954553525558006634667871247",
"25221398953477883946071053343003617794",
"234035373975345325209823024504321088420",
"312202502942048158891504209263974476402",
"146079265351114528825722374518087038469",
"185415868238709014188565328013855501653",
"207807344786254821213472992606983140866",
"264126712327134309109389835259632374462",
"291932016592696410096561113883698631289",
"277512520633384723821202764082142176805",
"169638336873034007754753134076815219945",
"81583980342962803435270583454082092790",
"284612551039558522568777820820930564858",
"49872357114778658701631759703456661732"
],
"threshold": 0.9
},
"id": "CVE-2026-43616-dd0067b1",
"target": {
"file": "xarchive.cpp"
},
"source": "https://github.com/horsicq/xarchive/commit/6a2aa84c2fd120b704f76bb5c5ee3e9b5a7a0fcc",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-43616.json"
"2026-08-12T10:15:55Z"