CVE-2026-47121 | sparkle-project Sparkle up to 2.9.1 Autoupdate SPUSparkleDeltaArchive.m extractItem path traversal

SecurityVulns

A vulnerability, which was classified as very critical, has been found in sparkle-project Sparkle up to 2.9.1. This affects the function extractItem of the file Autoupdate/SUBinaryDeltaApply.m/Autoupdate/SPUSparkleDeltaArchive.m of the component Autoupdate/SUBinaryDeltaApply/SPUSparkleDeltaArchive. This manipulation causes path traversal.

The identification of this vulnerability is CVE-2026-47121. It is possible to initiate the attack remotely. There is no exploit available.VulDB Recent EntriesRead More