LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-43888

CVE-2026-43888 - Vulnerability Analysis

HighCVSS: 8.7

Last Updated: May 12, 2026

Outline - Path Traversal

Published: May 11, 2026Updated: May 12, 2026Remote Exploitable

Overview

Outline < 1.7.0 contains a path traversal caused by improper handling of long nested zip entry paths in ZipHelper.extract, letting attackers write files outside the extraction sandbox, exploit requires crafted zip archive.

Severity & Score

Severity: High
CVSS Score: 8.7

Impact

Attackers can write files outside the intended directory, potentially leading to arbitrary file write and persistence on the system.

Mitigation

Update to version 1.7.0 or later.

Details

CVE ID
CVE-2026-43888
Severity
High
CVSS Score
8.7
Type
path_traversal
Status
rejected

CWE

  • CWE-22

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H