What is CVE-2026-63134?
CVE-2026-63134 is a vulnerability in the `safe-extract.py` script of the Malcolm network traffic analysis suite prior to version 26.07.0. A directory creation function lacks path traversal protection during archive extraction, which could allow unauthorized file writes. Users should update to version 26.07.0 or later.
Azərbaycanca: CVE-2026-63134, Malcolm şəbəkə trafik analiz alətində `safe-extract.py` skriptindəki zəiflikdir. 26.07.0 versiyasından əvvəl, arxivdən fayl çıxararkən qovluq yaratma əməliyyatında path traversal qorunması yoxdur, bu da uzaqdan kod icrasına səbəb ola bilər. İstifadəçilər 26.07.0 və ya daha yeni versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
In which component of Malcolm was CVE-2026-63134 found?
The vulnerability is in the `safe-extract.py` script of the Malcolm network traffic analysis suite.
Which version should users update to in order to mitigate CVE-2026-63134?
Users should update to Malcolm version 26.07.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.