CVE-2026-40024: Sleuthkit The Sleuth Kit
High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.
The Sleuth Kit through 4.14.0 contains a path traversal vulnerability in tsk_recover that allows an attacker to write files to arbitrary locations outside the intended recovery directory via crafted filenames or directory paths with path traversal sequences in a filesystem image. An attacker can craft a malicious filesystem image with embedded /../ sequences in filenames that, when processed by tsk_recover, writes files outside the output directory, potentially achieving code execution by overwriting shell configuration or cron entries.
Affected products
- Sleuthkit The Sleuth Kit: before 4.15.0 (fixed in 4.15.0)
Published 2026-04-08. Last modified 2026-07-25.