PT-2026-31461 · Unknown · The Sleuth Kit
CVSS v4.0
8.4
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
The Sleuth Kit versions through 4.14.0
Description
The Sleuth Kit’s
tsk recover component contains a path traversal flaw. An attacker can exploit this to write files to locations outside the intended recovery directory by using crafted filenames or directory paths within a filesystem image that include path traversal sequences. Specifically, crafting a malicious filesystem image with embedded '/../' sequences in filenames allows an attacker to write files outside the output directory when processed by tsk recover, potentially leading to code execution by overwriting system files like shell configurations or cron entries.Recommendations
Update versions of The Sleuth Kit to a version later than 4.14.0.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
The Sleuth Kit