LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-32733

CVE-2026-32733 - Vulnerability Analysis

MediumCVSS: 6.5

Last Updated: March 23, 2026

Halloy - Path Traversal

Published: March 20, 2026Updated: March 23, 2026PoC AvailableRemote Exploitable

Overview

Halloy contains a path traversal vulnerability caused by unsanitized filenames in DCC SEND requests, letting remote IRC users write files outside the configured save directory, exploit requires auto-accept enabled.

Severity & Score

Severity: Medium
CVSS Score: 6.5

Impact

Remote attackers can write files outside the intended directory, potentially overwriting sensitive files and compromising the system.

Mitigation

Update to the version including commit 0f77b2cfc5f822517a256ea5a4b94bad8bfe38b6 or later.

Details

CVE ID
CVE-2026-32733
Severity
Medium
CVSS Score
6.5
Type
path_traversal
Status
confirmed

CWE

  • CWE-22

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N