Impact
This vulnerability is a directory traversal flaw in Menyoo 2.0 prior to commit 729aa48 that permits a local attacker to craft specially named files through the Spooner file management, VehicleSpawner save/folder/rename, WeaponOptions save/folder/rename, and PedComponentChanger create folder/createfile/rename interfaces. By inserting traversal sequences the attacker can force the application to reference files outside of its intended directories, enabling the execution of arbitrary code and compromising the confidentiality, integrity, and availability of the target system. The weakness corresponds to CWE‑22, a classic path‑traversal vulnerability.
Affected Systems
The flaw exists in all builds of Menyoo 2.0 that were released before commit 729aa48. No specific vendor or product enumeration beyond Menyoo is available, and version data is limited to the commit boundary.
Risk and Exploitability
The EPSS score is listed at less than 1%, indicating a very low probability that the vulnerability is actively exploited in the wild at this time. The vulnerability is not included in the CISA KEV catalog, further suggesting that no reported exploits exist. However, the attack vector is local, meaning a user with write access to the installation directory can exploit the traversal. By inserting '..' sequences into the file‑management, VehicleSpawner, WeaponOptions, or PedComponentChanger interfaces, the application can be tricked into creating and executing files outside its intended directory, effectively allowing arbitrary code execution and compromising confidentiality, integrity, and availability of the system.
OpenCVE Enrichment