CVE-2024-57966: Kde Ark

Medium severity, CVSS 5.0. EPSS: 0.3% chance of exploitation in the next 30 days.

libarchiveplugin.cpp in KDE ark before 24.12.0 can extract to an absolute path from an archive.

Affected products

  • Kde Ark: before 24.12.0 (fixed in 24.12.0)

Published 2025-02-03. Last modified 2026-06-17.