CVE-2026-42532: Visidata

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

A path traversal vulnerability exists in the EmailSheet extract_parts functionality of VisiData (version(s): dev (commit 38b21f78)). A specially crafted .eml file can lead to arbitrary file write. An attacker can provide a malicious file to trigger this vulnerability.

Affected products

Published 2026-10-07. Last modified 2026-10-07.