Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Malcolm version 26.07.0 addresses these issues. For more information, see https://github.com/cisagov/Malcolm/pull/1043
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 02 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
cvssV4_0
|
Thu, 13 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cisagov
Cisagov malcolm |
|
| Vendors & Products |
Cisagov
Cisagov malcolm |
Tue, 11 Aug 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction with libarchive's secure flags, but creates directory entries with a raw `os.makedirs(os.path.join(dest, entry.pathname))` that has no traversal protection. An uploaded malicious archive containing a directory entry with a `../` sequence or an absolute path causes the filebeat processing container to create directories outside the intended extraction directory. Version 26.07.0 fixes the issue. | |
| Title | Malcolm's Path Traversal in Archive Extraction Allows Arbitrary Directory Creation | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-02T20:23:35.980Z
Reserved: 2026-07-15T16:54:55.817Z
Link: CVE-2026-63134
Updated: 2026-08-13T15:00:25.754Z
Status : Awaiting Analysis
Published: 2026-08-11T21:17:44.307
Modified: 2026-10-02T21:16:55.983
Link: CVE-2026-63134
No data.
OpenCVE Enrichment
Updated: 2026-10-02T21:30:18Z
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')