PT-2026-31461 · Unknown · The Sleuth Kit

·

CVE-2026-40024

·

Published

2026-04-08

·

Updated

2026-04-17

CVSS v4.0

8.4

High

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions The Sleuth Kit versions through 4.14.0
Description The Sleuth Kit’s tsk recover component contains a path traversal flaw. An attacker can exploit this to write files to locations outside the intended recovery directory by using crafted filenames or directory paths within a filesystem image that include path traversal sequences. Specifically, crafting a malicious filesystem image with embedded '/../' sequences in filenames allows an attacker to write files outside the output directory when processed by tsk recover, potentially leading to code execution by overwriting system files like shell configurations or cron entries.
Recommendations Update versions of The Sleuth Kit to a version later than 4.14.0.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40024
OESA-2026-1934
OESA-2026-1935
OESA-2026-1936
OESA-2026-1937
OESA-2026-1938
OESA-2026-1939

Affected Products

The Sleuth Kit