CVE-2026-32733 - Vulnerability Analysis
MediumCVSS: 6.5Last Updated: March 23, 2026
Halloy - Path Traversal
Published: March 20, 2026Updated: March 23, 2026PoC AvailableRemote Exploitable
Overview
Halloy contains a path traversal vulnerability caused by unsanitized filenames in DCC SEND requests, letting remote IRC users write files outside the configured save directory, exploit requires auto-accept enabled.
Severity & Score
Severity: Medium
CVSS Score: 6.5
Impact
Remote attackers can write files outside the intended directory, potentially overwriting sensitive files and compromising the system.
Mitigation
Update to the version including commit 0f77b2cfc5f822517a256ea5a4b94bad8bfe38b6 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-32733
- Severity
- Medium
- CVSS Score
- 6.5
- Type
- path_traversal
- Status
- confirmed
CWE
- CWE-22
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N