CVE-2026-43616
7.1horsicq · Detect-It-Easy
Detect-It-Easy prior to version 3.21 contains a path traversal vulnerability that allows attackers to achieve arbitrary file write and persistent code execution.
Executive summary
A path traversal vulnerability in Detect-It-Easy prior to version 3.21 allows local attackers to write arbitrary files and achieve persistent code execution via crafted archive entries.
Vulnerability
This vulnerability is a relative path traversal flaw stemming from insufficient path normalization during archive extraction, which can be triggered by an unauthenticated local attacker requiring user interaction.
Business impact
A successful exploit allows malicious actors to overwrite critical system files and user startup scripts, leading to persistent code execution and complete compromise of the affected host. With a CVSS score of 7.1 placing it in the high severity range, organizations face significant risks of unauthorized system access and operational disruption.
Remediation
Immediate Action: Update horsicq DIE-engine to version 3.21.0 or later to resolve the path traversal flaw.
Proactive Monitoring: Monitor file system activity for unexpected modifications to startup scripts and sensitive system directories.
Compensating Controls: Restrict user permissions on endpoints and ensure users only open archives from trusted sources to minimize the risk of malicious extraction.
Exploitation status
Public Exploit Available: No (no confirmed public exploit in available data)
Analyst recommendation
Security teams must treat this high-severity vulnerability with urgency due to the potential for persistent code execution. Administrators should apply the vendor-provided update to version 3.21.0 immediately across all endpoints running the affected software.
Sources
Originally found and disclosed by Mobasi Security Team, per the CVE Program record.