CVE-2020-23172: Kuba Project Kuba

Medium severity, CVSS 5.5. EPSS: 0.7% chance of exploitation in the next 30 days.

A vulnerability in all versions of Kuba allows attackers to overwrite arbitrary files in arbitrary directories with crafted Zip files due to improper validation of file paths in .zip archives.

Affected products

Published 2021-08-10. Last modified 2026-06-17.