Impact
A path traversal flaw exists in the EmailSheet extract_parts feature of VisiData. By supplying a specially crafted .eml file, an attacker can cause the program to write files to arbitrary locations on the filesystem. The vulnerability is a classic Path Traversal weakness (CWE-22), and if an attacker can write executable or privileged configuration files, this could enable remote code execution or significant privilege escalation. The CVSS score of 5.5 indicates a moderate severity, with potential impact on confidentiality, integrity, and availability.
Affected Systems
The flaw affects VisiData, a data exploration toolkit, in development builds up to commit 38b21f78. The affected component is the EmailSheet extract_parts logic that processes incoming .eml files. Users running these unpatched builds should be considered vulnerable. No specific distribution versions are listed beyond the commit identifier.
Risk and Exploitability
The vulnerability requires the attacker to supply a malicious .eml file to the target application; thus the likely attack vector is an authenticated or local file injection scenario where the user can control the input. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, suggesting no currently known exploits. Nonetheless, the moderate CVSS implies that an exploit would be reasonably valuable. Administrators should treat this as a potential risk, especially if VisiData handles untrusted email files in production environments.
OpenCVE Enrichment