CVE-2026-82264

Source
https://cve.org/CVERecord?id=CVE-2026-82264
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82264.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-82264
Published
2026-08-28T16:18:49Z
Modified
2026-08-30T03:48:22Z
Severity
  • 6.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Duplicacy Path Traversal during Restore via Unsanitized Snapshot Paths
Details

Duplicacy through 3.2.5 contains a path traversal vulnerability in the restore function that fails to validate entry paths deserialized from snapshot files. Attackers can craft malicious snapshot entries with directory traversal sequences to write files outside the restore directory to arbitrary locations accessible by the restoring user.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82264.json"
}
References

Affected packages

Git / github.com/gilbertchen/duplicacy

Affected ranges

Type
GIT
Repo
https://github.com/gilbertchen/duplicacy
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.2.5"
        },
        {
            "fixed": "3.2.5"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

v0.*
v0.1.1
v0.1.10
v0.1.5
v0.1.6
v0.1.7
v0.1.8
v1.*
v1.0.0
v1.0.1
v1.1.0
v1.1.3
v1.1.4
v1.1.5
v1.1.6
v1.1.8
v1.1.9
v1.2.0
v1.2.1
v1.2.3
v1.2.4
v1.2.5
v2.*
v2.0.0
v2.0.10
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v2.0.6
v2.0.7
v2.0.9
v2.1.0
v2.1.1
v2.1.2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.4.0
v2.4.1
v2.5.0
v2.5.1
v2.5.2
v2.6.0
v2.6.1
v2.6.2
v2.7.0
v2.7.1
v2.7.2
v3.*
v3.0.0
v3.0.1
v3.1.0
v3.2.0
v3.2.1
v3.2.2
v3.2.3
v3.2.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82264.json"