<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Gopeed - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/gopeed/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 20 Sep 2026 00:16:09 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/gopeed/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Path Traversal Vulnerability in Gopeed Archive Extraction</title><link>https://feed.craftedsignal.io/briefs/2026-09-gopeed-traversal/</link><pubDate>Sun, 20 Sep 2026 00:16:09 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-gopeed-traversal/</guid><description>Gopeed through version 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows an attacker to write arbitrary files outside the designated directory when the AutoExtract feature is enabled.</description><content:encoded><![CDATA[<p>Gopeed versions up to and including 2.0.0-beta.3 are susceptible to a path traversal vulnerability during the archive extraction process. This flaw stems from improper validation of file paths within archive entries. When a user downloads a malicious archive and leverages the software's AutoExtract functionality, an attacker can utilize directory traversal sequences (such as ../) within the archive's internal path structure to escape the intended extraction folder. This capability allows the attacker to write or overwrite arbitrary files on the victim's filesystem. Successful exploitation could lead to system compromise, such as overwriting configuration files or placing malicious executables in startup directories, resulting in unauthorized code execution or persistence. This issue specifically impacts instances where the AutoExtract feature is actively enabled by the end user.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows for arbitrary file writes on the host system, which can result in full system compromise, loss of data integrity, and unauthorized remote code execution. Users in any sector utilizing Gopeed for file downloads are at risk if they enable the AutoExtract feature and process untrusted archives.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security teams:</p>
<ul>
<li>Identify and audit all instances of Gopeed version 2.0.0-beta.3 or earlier across the environment.</li>
<li>Disable the AutoExtract feature in Gopeed settings across all managed endpoints until an official patch is applied.</li>
<li>Monitor for unauthorized file modifications in sensitive directories (e.g., startup folders, system binaries) if Gopeed is in use.</li>
<li>Upgrade all Gopeed installations to a version released after 2.0.0-beta.3 once the vendor provides a remediation.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>path-traversal</category><category>vulnerability</category><category>file-write</category></item></channel></rss>