CVE-2026-102262: Newell Brands DYMO ID parent directory open to path traversal through improper spheres of control
Newell Brands DYMO ID 1.5.1.71 resolves its plugin Modules directory relative to the process working directory. An attacker could store a job file alongside malicious modules / DLL that sets the process working directory to the job file's folder when a victim clicks on the file, resulting in code execution at the victim's privilege level. Fixed in 1.6.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Newell Brands DYMO IDto a version that resolves this vulnerability.Fixed in 1.6.0
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Users running DYMO ID 1.5.1.71 who open a crafted job file are exposed. Successful exploitation runs code at the privilege level of the user who clicks the file.
What must an attacker provide or persuade a victim to do?
The attacker must place a job file alongside malicious modules or DLLs and induce a victim to click the job file. Opening the file causes the process working directory to be set to the job file's folder, allowing the malicious modules to be resolved.
What should be done if the affected version is deployed?
Update DYMO ID to version 1.6.0, which fixes the issue. Until updated, avoid opening job files from untrusted locations or sources, especially where accompanying files may be present.