CVE-2026-43616

7.1

horsicq · Detect-It-Easy

Detect-It-Easy prior to version 3.21 contains a path traversal vulnerability that allows attackers to achieve arbitrary file write and persistent code execution.

Executive summary

A path traversal vulnerability in Detect-It-Easy prior to version 3.21 allows local attackers to write arbitrary files and achieve persistent code execution via crafted archive entries.

Vulnerability

This vulnerability is a relative path traversal flaw stemming from insufficient path normalization during archive extraction, which can be triggered by an unauthenticated local attacker requiring user interaction.

Business impact

A successful exploit allows malicious actors to overwrite critical system files and user startup scripts, leading to persistent code execution and complete compromise of the affected host. With a CVSS score of 7.1 placing it in the high severity range, organizations face significant risks of unauthorized system access and operational disruption.

Remediation

Immediate Action: Update horsicq DIE-engine to version 3.21.0 or later to resolve the path traversal flaw.

Proactive Monitoring: Monitor file system activity for unexpected modifications to startup scripts and sensitive system directories.

Compensating Controls: Restrict user permissions on endpoints and ensure users only open archives from trusted sources to minimize the risk of malicious extraction.

Exploitation status

Public Exploit Available: No (no confirmed public exploit in available data)

Analyst recommendation

Security teams must treat this high-severity vulnerability with urgency due to the potential for persistent code execution. Administrators should apply the vendor-provided update to version 3.21.0 immediately across all endpoints running the affected software.

Sources

Originally found and disclosed by Mobasi Security Team, per the CVE Program record.