CVE-2026-45384

Source
https://cve.org/CVERecord?id=CVE-2026-45384
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45384.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-45384
Aliases
  • GHSA-wjch-42rm-q53h
Published
2026-06-10T20:00:19.899Z
Modified
2026-07-15T01:49:20.896105312Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L CVSS Calculator
Summary
bit7z: Arbitrary File Overwrite via Symlink Attack on Predictable Temp File During Archive Update
Details

bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4.0.12, there is an arbitrary file overwrite vulnerability via symlink attack on predictable temp files during archive update. This issue has been patched in version 4.0.12.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45384.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-377",
        "CWE-59"
    ]
}
References

Affected packages

Git / github.com/rikyoz/bit7z

Affected ranges

Type
GIT
Repo
https://github.com/rikyoz/bit7z
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "4.0.12"
        }
    ]
}

Affected versions

v1.*
v1.0.0
v1.0.0-beta.2
v1.0.0-rc
v2.*
v2.0.0
v2.0.0-beta
v2.1.0
v3.*
v3.0.0
v3.0.0-beta
v3.0.1
v3.1.0
v3.1.0-beta
v3.1.1
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.2.0
v4.*
v4.0.0
v4.0.0-rc
v4.0.1
v4.0.10
v4.0.11
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45384.json"