HIGH
GopeedLab
CVE published 2026-09-19
CVE-2026-93992
CVE-2026-93992 is a path traversal vulnerability in Gopeed through 2.0.0-beta.3. This vulnerability allows attackers to write arbitrary files outside the extraction directory when users download and extract archives with AutoExtract enabled. The vulnerability is caused by inadequate validation of archive entries, enabling attackers to bypass security measures and write files to arbitrary locations. Defend [truncated]