CVE-2026-40024: Sleuth Kit tsk_recover Path Traversal

Published Apr 8, 2026
·
Updated

Sleuth Kit tskrecover Path Traversal

Other sources

The Sleuth Kit through 4.14.0 contains a path traversal vulnerability in tskrecover that allows an attacker to write files to arbitrary locations outside the intended recovery directory via crafted filenames or directory paths with path traversal sequences in a filesystem image. An attacker can craft a malicious filesystem image with embedded /../ sequences in filenames that, when processed by tskrecover, writes files outside the output directory, potentially achieving code execution by overwriting shell configuration or cron entries.

NVD

Affected Software

2 affected componentsFixes available
Microsoft azl3 sleuthkit 4.12.1-1
sleuthkit The Sleuth Kit<4.15.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Sleuth Kit tsk_recover to a version that resolves this vulnerability.

    Fixed in 4.14.0
  2. Compensating control

    When using Sleuth Kit tsk_recover, process only trusted filesystem images to reduce exposure to crafted filenames/directories containing path traversal sequences (e.g., '/../') that could write outside the intended recovery directory.

Event History

Apr 8, 2026
CVE Published
via MITRE·09:35 PM
Data Sourced
via MITRE·09:35 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 10, 2026
Data Sourced
via Microsoft·08:01 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:01 AM
DescriptionSeverity

Frequently Asked Questions

1

What is the severity of CVE-2026-40024?

CVE-2026-40024 is classified as a medium-severity path traversal vulnerability.

2

How do I fix CVE-2026-40024?

To fix CVE-2026-40024, upgrade the Sleuth Kit to version 4.15.0 or later.

3

What impact does CVE-2026-40024 have?

CVE-2026-40024 allows attackers to write files to arbitrary locations outside the intended recovery directory.

4

Which versions of Sleuth Kit are affected by CVE-2026-40024?

CVE-2026-40024 affects Sleuth Kit versions 4.14.0 and earlier.

5

What should I do if I cannot upgrade due to compatibility issues related to CVE-2026-40024?

If upgrading is not possible, it is recommended to restrict access to the vulnerable application and monitor for any unauthorized activity.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203