Description
A path traversal vulnerability exists in the EmailSheet extract_parts functionality of VisiData (version(s): dev (commit 38b21f78)). A specially crafted .eml file can lead to arbitrary file write. An attacker can provide a malicious file to trigger this vulnerability.
Published: 2026-10-07
Score: 5.5 Medium
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Assess Impact
AI Analysis

Impact

A path traversal flaw exists in the EmailSheet extract_parts feature of VisiData. By supplying a specially crafted .eml file, an attacker can cause the program to write files to arbitrary locations on the filesystem. The vulnerability is a classic Path Traversal weakness (CWE-22), and if an attacker can write executable or privileged configuration files, this could enable remote code execution or significant privilege escalation. The CVSS score of 5.5 indicates a moderate severity, with potential impact on confidentiality, integrity, and availability.

Affected Systems

The flaw affects VisiData, a data exploration toolkit, in development builds up to commit 38b21f78. The affected component is the EmailSheet extract_parts logic that processes incoming .eml files. Users running these unpatched builds should be considered vulnerable. No specific distribution versions are listed beyond the commit identifier.

Risk and Exploitability

The vulnerability requires the attacker to supply a malicious .eml file to the target application; thus the likely attack vector is an authenticated or local file injection scenario where the user can control the input. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, suggesting no currently known exploits. Nonetheless, the moderate CVSS implies that an exploit would be reasonably valuable. Administrators should treat this as a potential risk, especially if VisiData handles untrusted email files in production environments.

Generated by OpenCVE AI on October 7, 2026 at 15:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade VisiData to a non‑vulnerable release when available.
  • Limit filesystem write permissions for the VisiData execution user to the directories it legitimately needs.
  • Configure the application to reject or sanitize file paths derived from .eml attachments before writing, or disable the EmailSheet extract_parts feature if not required.

Generated by OpenCVE AI on October 7, 2026 at 15:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
Title Path Traversal in VisiData Email Processing Enables Arbitrary File Write

Wed, 07 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 13:00:00 +0000

Type Values Removed Values Added
Description A path traversal vulnerability exists in the EmailSheet extract_parts functionality of VisiData (version(s): dev (commit 38b21f78)). A specially crafted .eml file can lead to arbitrary file write. An attacker can provide a malicious file to trigger this vulnerability.
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: talos

Published:

Updated: 2026-10-07T14:38:42.745Z

Reserved: 2026-04-29T13:37:19.017Z

Link: CVE-2026-42532

cve-icon Vulnrichment

Updated: 2026-10-07T14:38:38.418Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-07T13:17:22.617

Modified: 2026-10-07T16:02:27.613

Link: CVE-2026-42532

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T15:30:17Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')