CVE-2026-41958
Awaiting Analysis Awaiting Analysis - Queue

Path Traversal in VisiData via Malicious ZIP File

Vulnerability report for CVE-2026-41958, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: Talos

Description

A path traversal vulnerability exists in the unzip_http RemoteZipFile extract functionality of VisiData (version(s): dev (commit 38b21f78)). A specially crafted .zip file can lead to arbitrary file write. An attacker can provide a crafted URL to trigger this vulnerability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
visidata visidata dev (commit 38b21f78)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a path traversal vulnerability in VisiData's unzip_http RemoteZipFile extract functionality. It allows a specially crafted .zip file to write arbitrary files to any location on the filesystem writable by the victim's user. The issue occurs because VisiData does not sanitize filenames from the zip archive before writing them to disk, enabling path traversal sequences like ../../ to escape the intended extraction directory.

Detection Guidance

To detect this vulnerability, monitor for unusual file writes or unexpected network activity from VisiData processes. Check for suspicious .zip files downloaded from untrusted sources. Use commands like 'lsof' or 'netstat' to track file operations and network connections initiated by VisiData.

Impact Analysis

An attacker can exploit this by providing a malicious URL to a VisiData user. If the user opens the URL and triggers extraction, the attacker could write arbitrary files to any writable location on the system. This could lead to data corruption, unauthorized file creation, or potential execution of malicious code depending on the files written.

Compliance Impact

This vulnerability could potentially violate compliance with GDPR or HIPAA if exploited to write sensitive files to unauthorized locations. Arbitrary file writes may expose or modify protected data, leading to unauthorized access or data breaches. However, the provided context does not explicitly detail compliance impacts.

Mitigation Strategies

Immediately update VisiData to the latest version or commit that patches this issue. Avoid opening .zip files from untrusted sources. Disable the unzip_http RemoteZipFile functionality if not required. Monitor filesystem writes for unexpected activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-41958. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart