OVERVIEW CVE-2026-40024 is a path traversal vulnerability in The Sleuth Kit through version 4.14.0, specifically affecting the tsk_recover utility. The vulnerability enables attackers to write files to arbitrary locations outside the intended recovery directory by exploiting path traversal sequences (/../) embedded in crafted filesystem image filenames or directory paths. SEVERITY This vulnerability carries a CVSS v3.1 score of 7.1 (HIGH) with a local attack vector requiring user interaction but no elevated privileges. The impact is significant, permitting both confidentiality and integrity compromise through arbitrary file write capabilities. An attacker could potentially achieve code execution by overwriting shell configuration files or cron entries, though availability is not directly affected. The FAUCET Risk Score of 47.0/100 indicates moderate overall risk. EXPLOITATION STATUS There is no evidence of active exploitation in the wild. The vulnerability does not appear on CISA's Known Exploited Vulnerabilities (KEV) catalog and is classified as inactive on vulnerability hotlists. The EPSS score of 0.0004 suggests minimal probability of exploitation in the near term. However, the relative simplicity of the attack vector and the potential for post-exploitation persistence through file overwrites warrants monitoring for future proof-of-concept release or weaponization.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.15.0CPE matchmatch criteria | cpe:2.3:a:sleuthkit:the_sleuth_kit:*:*:*:*:*:*:*:* | ||
>= 0, <= 4.14.0CPE match | cpe:2.3:a:sleuthkit:the_sleuth_kit:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.