{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/gopeed/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:gopeed:gopeed:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-93992"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Gopeed (\u003c= 2.0.0-beta.3)"],"_cs_severities":["high"],"_cs_tags":["path-traversal","vulnerability","file-write"],"_cs_type":"advisory","_cs_vendors":["Gopeed"],"content_html":"\u003cp\u003eGopeed versions up to and including 2.0.0-beta.3 are susceptible to a path traversal vulnerability during the archive extraction process. This flaw stems from improper validation of file paths within archive entries. When a user downloads a malicious archive and leverages the software's AutoExtract functionality, an attacker can utilize directory traversal sequences (such as ../) within the archive's internal path structure to escape the intended extraction folder. This capability allows the attacker to write or overwrite arbitrary files on the victim's filesystem. Successful exploitation could lead to system compromise, such as overwriting configuration files or placing malicious executables in startup directories, resulting in unauthorized code execution or persistence. This issue specifically impacts instances where the AutoExtract feature is actively enabled by the end user.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows for arbitrary file writes on the host system, which can result in full system compromise, loss of data integrity, and unauthorized remote code execution. Users in any sector utilizing Gopeed for file downloads are at risk if they enable the AutoExtract feature and process untrusted archives.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify and audit all instances of Gopeed version 2.0.0-beta.3 or earlier across the environment.\u003c/li\u003e\n\u003cli\u003eDisable the AutoExtract feature in Gopeed settings across all managed endpoints until an official patch is applied.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized file modifications in sensitive directories (e.g., startup folders, system binaries) if Gopeed is in use.\u003c/li\u003e\n\u003cli\u003eUpgrade all Gopeed installations to a version released after 2.0.0-beta.3 once the vendor provides a remediation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-20T00:16:09Z","date_published":"2026-09-20T00:16:09Z","id":"https://feed.craftedsignal.io/briefs/2026-09-gopeed-traversal/","summary":"Gopeed through version 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows an attacker to write arbitrary files outside the designated directory when the AutoExtract feature is enabled.","title":"Path Traversal Vulnerability in Gopeed Archive Extraction","url":"https://feed.craftedsignal.io/briefs/2026-09-gopeed-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Gopeed","version":"https://jsonfeed.org/version/1.1"}