CVE-2026-42532
Awaiting Analysis Awaiting Analysis - Queue

Path Traversal in VisiData EmailSheet

Vulnerability report for CVE-2026-42532, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: Talos

Description

A path traversal vulnerability exists in the EmailSheet extract_parts functionality of VisiData (version(s): dev (commit 38b21f78)). A specially crafted .eml file can lead to arbitrary file write. An attacker can provide a malicious file to trigger this vulnerability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
visidata visidata dev (commit 38b21f78)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a path traversal vulnerability in VisiData's EmailSheet extract_parts function. It allows a specially crafted .eml file to write arbitrary files outside the intended directory. The issue occurs when a malicious .eml file contains a MIME part with a filename parameter using path traversal sequences like ../. When a user opens the file and extracts attachments, the malicious file is written to the traversed path.

Detection Guidance

To detect this vulnerability, monitor for suspicious .eml files with MIME parts containing path traversal sequences like '../' in filenames. Check for unexpected file writes outside intended directories, especially in user home directories or system paths. Review VisiData logs for extract_parts function usage with malformed filenames.

Impact Analysis

An attacker could overwrite sensitive files such as shell initialization files or SSH authorized keys. This could lead to system compromise, unauthorized access, or further attacks. Exploitation requires user interaction to open the malicious .eml file and trigger extraction.

Compliance Impact

This vulnerability could lead to unauthorized file writes, potentially compromising data integrity and confidentiality. This may violate GDPR's data protection principles or HIPAA's security requirements for safeguarding sensitive information.

Mitigation Strategies

Immediately update VisiData to the latest version that patches this vulnerability. Avoid opening untrusted .eml files in VisiData. Implement file integrity monitoring to detect unauthorized file modifications. Restrict write permissions in directories where VisiData extracts files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-42532. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart