CVE 6.1 MEDIUM

bit7z: Arbitrary File Overwrite via Symlink Attack on Predictable Temp File During Archive Update_CVE-2026-45384

6.1 / 10
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L

Description

bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4.0.12, there is an arbitrary file overwrite vulnerability via symlink attack on predictable temp files during archive update. This issue has been patched in version 4.0.12.

Basic Information

ID CVE-2026-45384
Source GitHub_M
Published Jun 10, 2026 at 20:00

Affected Product

Vendor rikyoz
Product bit7z
Version < 4.0.12
Affected Versions rikyoz bit7z < 4.0.12

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.