← Vulnerability feed

Vulnerability record · CVE-2026-40024 · published 8 April 2026

CVE-2026-40024: Sleuthkit the sleuth kit path traversal vulnerability

Sleuthkit · The Sleuth Kit

The Sleuth Kit through 4.14.0 contains a path traversal vulnerability in tsk_recover that allows an attacker to write files to arbitrary locations outside the intended recovery directory via crafted filenames or directory paths with path traversal sequences in a filesystem image. An attacker can craft a malicious filesystem image with embedded /../ sequences in filenames that, when processed by tsk_recover, writes files outside the output directory, potentially achieving code execution by overwriting shell configuration or cron entries.

8.4 CVSS 4.0 High EPSS 0.21% · top 90.3% CWE-22 · Path traversal
8.4CVSS 4.0 base score
0.21%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
25 Jul 2026Last modified by NVD

Description

The Sleuth Kit through 4.14.0 contains a path traversal vulnerability in tsk_recover that allows an attacker to write files to arbitrary locations outside the intended recovery directory via crafted filenames or directory paths with path traversal sequences in a filesystem image. An attacker can craft a malicious filesystem image with embedded /../ sequences in filenames that, when processed by tsk_recover, writes files outside the output directory, potentially achieving code execution by overwriting shell configuration or cron entries.

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-40024 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-10232Sleuthkit the sleuth kit out-of-bounds write vulnerabilityIn version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file timestamp parsing logic in yaf…EPSS 2.5%9.8CVE-2019-14531Sleuthkit the sleuth kit out-of-bounds read vulnerabilityAn issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an out of bounds read on iso9660 while parsing System Use Sharing Protocol data in fs…EPSS 1.8%9.8CVE-2019-14532Sleuthkit the sleuth kit vulnerabilityAn issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an off-by-one overwrite due to an underflow on tools/hashtools/hfind.cpp while using …EPSS 2.1%9.1CVE-2020-10233Sleuthkit the sleuth kit out-of-bounds read vulnerabilityIn version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a heap-based buffer over-read in ntfs_dinode_lookup in fs/ntfs.c.EPSS 2.4%8.1CVE-2018-11737Sleuthkit the sleuth kit out-of-bounds read vulnerabilityAn issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found…EPSS 1.3%8.1CVE-2018-11738Sleuthkit the sleuth kit out-of-bounds read vulnerabilityAn issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was found…EPSS 1.3%8.1CVE-2018-11739Sleuthkit the sleuth kit out-of-bounds read vulnerabilityAn issue was discovered in libtskimg.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was foun…EPSS 1.3%8.1CVE-2018-11740Sleuthkit the sleuth kit out-of-bounds read vulnerabilityAn issue was discovered in libtskbase.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory region was fou…EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2026-40024), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.