Impact
The vulnerability resides in the archive extraction logic of Gopeed before version 2.0.0‑beta.3. Malicious archives containing directory traversal sequences can bypass the validation check, allowing an attacker to write files outside the intended extraction directory. This can overwrite arbitrary system or application files, potentially causing data corruption or configuration tampering. The weakness is a classic path traversal (CWE‑22).
Affected Systems
The affected product is Gopeed from GopeedLab, specifically all releases up to and including 2.0.0‑beta.3. Any installation using this version bundle the flawed extraction routine.
Risk and Exploitability
The CVSS score of 7 denotes a medium to high severity. EPSS information is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting that it is not known to be actively exploited in the wild. The attack vector is user‑initiated: an attacker must craft an archive with traversal entries and get a Gopeed user to download and auto‑extract it. Because the flaw allows write operations to arbitrary paths, the impact can be significant if the attacker writes files that can alter configuration or application data.
OpenCVE Enrichment