CVE-2026-41958: Visidata

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

A path traversal vulnerability exists in the unzip_http RemoteZipFile extract functionality of VisiData (version(s): dev (commit 38b21f78)). A specially crafted .zip file can lead to arbitrary file write. An attacker can provide a crafted URL to trigger this vulnerability.

Affected products

Published 2026-10-07. Last modified 2026-10-07.