CVE-2020-23172: Kuba Project Kuba
Medium severity, CVSS 5.5. EPSS: 0.7% chance of exploitation in the next 30 days.
A vulnerability in all versions of Kuba allows attackers to overwrite arbitrary files in arbitrary directories with crafted Zip files due to improper validation of file paths in .zip archives.
Affected products
- Kuba Project Kuba: any version
Published 2021-08-10. Last modified 2026-06-17.