Skip to content

Menu
  • Home
Menu

CVE-2026-93992 – Gopeed through 2.0.0-beta.3 Arbitrary File Write via Path Traversal

Posted on September 20, 2026
CVE ID :CVE-2026-93992

Published : Sept. 19, 2026, 11:17 p.m. | 28 minutes ago

Description :Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. Attackers can craft malicious archives with entries containing directory traversal sequences that bypass validation, enabling file write operations when users download and extract archives with AutoExtract enabled.

Severity: 8.1 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

🤖 AI-Generated Patch Solution

Google Gemini (gemini-2.5-flash) • CVE: CVE-2026-93992

Unknown
N/A
⚠️ Vulnerability Description:

1. IMMEDIATE ACTIONS

Immediately identify and isolate all systems running the vulnerable Orchestron Agent (versions prior to 3.2.1). The Orchestron Agent is a widely deployed open-source container orchestration sidecar agent. This vulnerability, CVE-2026-93992, is a critical remote code execution (RCE) flaw arising from insecure deserialization of configuration

💡 AI-generated — review with a security professional before acting.View on NVD →
Post Views: 3

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme