CVE-2026-32733
Last modified
CVE-2026-32733 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Halloy is an IRC application written in Rust. Prior to commit 0f77b2cfc5f822517a256ea5a4b94bad8bfe38b6, the DCC receive flow did not sanitize filenames from incoming `DCC SEND` requests. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
Halloy is an IRC application written in Rust. Prior to commit 0f77b2cfc5f822517a256ea5a4b94bad8bfe38b6, the DCC receive flow did not sanitize filenames from incoming `DCC SEND` requests. A remote IRC user could send a filename with path traversal sequences like `../../.ssh/authorized_keys` and the file would be written outside the user's configured `save_directory`. With auto-accept enabled this required zero interaction from the victim. Starting with commit 0f77b2cfc5f822517a256ea5a4b94bad8bfe38b6, all identified code paths sanitize filenames through a shared `sanitize_filename` function.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Halloy | Halloy | <= 2026.4 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-32733?
How severe is CVE-2026-32733?
How do I fix CVE-2026-32733?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-32728Parse Server is an open source backend that can be deployed …7.6
- CVE-2026-32729Runtipi is a personal homeserver orchestrator. Prior to 4.8.…8.8
- CVE-2026-3273A vulnerability was identified in Tenda F453 1.0.0.3. Affect…8.8
- CVE-2026-32730ApostropheCMS is an open-source content management framework…8.1
- CVE-2026-32731ApostropheCMS is an open-source content management framework…9.9
- CVE-2026-32732Lean 4 VS Code Extension is a Visual Studio Code extension f…0
- CVE-2026-32734baserCMS is a website development framework. Prior to versio…6.1
- CVE-2026-32735openapi-to-java-records-mustache-templates allows users to g…2.3
- CVE-2026-32736The Hytale Modding Wiki is a free service for Hytale mods to…4.3
- CVE-2026-32737Romeo gives the capability to reach high code coverage of Go…10
- CVE-2026-32738libheif is a HEIF and AVIF file format decoder and encoder. …6.5
- CVE-2026-32739libheif is a HEIF and AVIF file format decoder and encoder. …6.5
Are you affected by CVE-2026-32733?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
