---
id: CVE-2026-41958
title: >-
  A path traversal vulnerability exists in the unzip_http RemoteZipFile extract
  functionality of VisiData (version(s): dev (commit 38b21f78))
summary: >-
  A path traversal vulnerability exists in the unzip_http RemoteZipFile extract
  functionality of VisiData (version(s): dev (commit 38b21f78)). A specially
  crafted .zip file can lead to arbitrary file write. An attacker can provide a
  crafte…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'
cwe:
  - CWE-22
vendor: visidata
product: visidata
affected:
  - visidata dev (commit 38b21f78)
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T13:17:22.467'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-41958'
references:
  - url: 'https://talosintelligence.com/vulnerability_reports/TALOS-2026-2414'
    label: talos-cna@cisco.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-07T13:31:04.599Z'
---

## Overview

A path traversal vulnerability exists in the unzip_http RemoteZipFile extract functionality of VisiData (version(s): dev (commit 38b21f78)). A specially crafted .zip file can lead to arbitrary file write. An attacker can provide a crafted URL to trigger this vulnerability.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
