CVE-2026-42448Low· 3.5▾ SunlitMagic Wormhole: receive, with --output pointing at an existing directory can be path-traversed
▾ Sunlit zone — Low / medium · no exploitation signal
impact 19.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.2%
A receiver who specifies "--output <dir>" where that output directory currently exists (as a directory).
0.24.0 will contain the patch
Ensure local target directories specified by "--output" do not already exist
Private email and Signal communications from a user. Magic Wormhole thanks @marduc812
magic-wormhole >= 0.23.0, < 0.24.0Upgrade to a patched release:
magic-wormhole 0.24.0Connected by shared product, vendor, weakness, or advisory.