PatchSiren

GopeedLab CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH GopeedLab CVE published 2026-09-19

CVE-2026-93992

CVE-2026-93992 is a path traversal vulnerability in Gopeed through 2.0.0-beta.3. This vulnerability allows attackers to write arbitrary files outside the extraction directory when users download and extract archives with AutoExtract enabled. The vulnerability is caused by inadequate validation of archive entries, enabling attackers to bypass security measures and write files to arbitrary locations. Defend [truncated]