CVE-2015-2060: Cabextract Project Cabextract

Medium severity, CVSS 5.3. EPSS: 2.3% chance of exploitation in the next 30 days.

cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash.

Affected products

Published 2019-11-29. Last modified 2026-06-17.