HackerOne Disclosed Reports - 2026-10-03

0 Replies, 10 Views

Logo
High
resolved

Path Traversal in mbstream Extract


Bug reported by Riley Scott Jacob was disclosed at October 3, 2026, 12:57 pm   |   Path Traversal

A path traversal vulnerability was discovered in the extraction code of a database backup utility. The vulnerability allowed malicious archive files to create files outside the intended target directory by using relative path traversal sequences. The flaw existed in the file path validation logic, which failed to reject directory traversal components in archive chunk paths. When extraction was performed, these traversal sequences were resolved by the kernel to write files to arbitrary locations on the filesystem where the extracting user had permissions. The vulnerability was confirmed to enable root-level command execution when extraction was performed with elevated privileges, through the creation of malicious configuration files in system directories.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]

Messages In This Thread
HackerOne disclosed reports - 2026-10-03 - by hashXploiter - Yesterday, 12:30 PM



Users browsing this thread: 1 Guest(s)