Impact
A path traversal flaw allows an attacker to write files to arbitrary locations inside the VisiData server by supplying a specially crafted ZIP file through the unzip_http RemoteZipFile feature. The flaw is a classic CWE‐22 vulnerability that can overwrite critical configuration or executable files, leading to modification of application behavior or privilege escalation. The primary impact is the ability for an attacker to tamper with the application’s files and potentially gain significant control over the system.
Affected Systems
The affected product is VisiData from the visidata:visidata vendor, specifically the development build identified by commit 38b21f78. No other official releases were listed as affected.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting lower but still real exploitation risk. The likely attack vector is remote, via a crafted URL that triggers the vulnerable unzip operation. Because the flaw allows writing beyond the intended directory, an attacker with network access to the VisiData instance can deploy tampered files without needing higher privileges. Overall, the risk is significant for systems exposed to untrusted input.
OpenCVE Enrichment