CVE-2026-32805 identifies a path traversal vulnerability in ctfer_io romeo versions prior to 0.2.2. This flaw, located in the `sanitizeArchivePath` function, allows a crafted tar archive to write files outside the intended destination directory due to a missing trailing path separator in a security check. Rated 7.5 HIGH (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N), it presents a network attack vector with high integrity impact. Despite its severity, there is currently no evidence of active exploitation, publicly available exploit code, or significant community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.2.2CPE matchmatch criteria | cpe:2.3:a:ctfer-io:romeo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.