CVE-2023-52138 is a critical path traversal vulnerability affecting Engrampa, the archive manager for the MATE desktop environment. This flaw allows an attacker to achieve full Remote Command Execution (RCE) by crafting a malicious CPIO or ISO archive that, upon extraction, writes arbitrary files to unintended locations due to Engrampa following symlinks. With a CVSS score of 9.6 (CRITICAL), the vulnerability has a low attack complexity and can lead to complete compromise of confidentiality, integrity, and availability. Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog, indicating no active exploitation. Community discussion and media coverage are minimal, suggesting a low level of public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.26.2CPE matchmatch criteria | cpe:2.3:a:mate-desktop:engrampa:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.