CVE-2026-63134 | cisagov Malcolm up to 26.6.x File Extraction safe-extract.py os.makedirs entry.pathname path traversal

SecurityVulns

A vulnerability marked as critical has been reported in cisagov Malcolm up to 26.6.x. The impacted element is the function os.makedirs of the file safe-extract.py of the component File Extraction. The manipulation of the argument entry.pathname leads to path traversal.

This vulnerability is uniquely identified as CVE-2026-63134. The attack is possible to be carried out remotely. No exploit exists.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More