CVE-2026-93992
Gopeed through 2.0.0-beta.3 Arbitrary File Write via Path Traversal
CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th
Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. Attackers can craft malicious archives with entries containing directory traversal sequences that bypass validation, enabling file write operations when users download and extract archives with AutoExtract enabled.
| CWE | CWE-22 |
| Vendor | gopeedlab |
| Product | gopeed |
| Published | Sep 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for gopeedlab gopeed
Be the first to know when new high vulnerabilities affecting gopeedlab gopeed are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
High
Affected Versions
GopeedLab / gopeed
0 โค 2.0.0-beta.3
References
github.com: https://github.com/GopeedLab/gopeed/issues/1525 github.com: https://github.com/GopeedLab/gopeed/commit/38750d8505274e55cf11aa77f0694c71dd82f519 github.com: https://github.com/GopeedLab/gopeed/blob/a5cd53f94c18ac65add684b1113fa5f0b47cc4da/pkg/download/extract_7z.go#L45-L53 github.com: https://github.com/GopeedLab/gopeed/blob/a5cd53f94c18ac65add684b1113fa5f0b47cc4da/pkg/download/extract.go#L284-L296 github.com: https://github.com/GopeedLab/gopeed vulncheck.com: https://www.vulncheck.com/advisories/gopeed-through-2.0.0-beta.3-arbitrary-file-write-via-path-traversal
Credits
Yu Sun