LOW
OSPG
CVE published 2026-04-27
CVE-2026-7179
A Path Traversal vulnerability was detected in OSPG binwalk up to 2.4.3. The issue affects the WinCE Extraction Plugin, specifically the read_null_terminated_string function in src/binwalk/plugins/winceextract.py. This vulnerability allows local attackers to manipulate the self.file_name argument, leading to path traversal. The exploit has been publicly disclosed. The project maintainer has confirmed the [truncated]