CVE Explorer
CVE-2026-27884
NetExec is a network execution tool. Prior to version 1.5.1, the module spider_plus improperly creates the output file and folder path when saving files from SMB shares. It does not take into account that it is possible for Linux SMB shares to have path traversal characters such as `../` in them. An attacker can craft a filename in an SMB share that includes these characters, which when spider_plus crawls and downloads, can write or overwrite arbitrary files. The issue is patched in v1.5.1. As a
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"NetExec","vendor":"Pennyw0rth","versions":[{"status":"affected","version":"< 1.5.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:d7411c1fb405c6789aec3b565b2761b250332efcc637fa5129a0c72c95d7a070 · sha256:c114388c8fdff25b… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:d7411c1fb405c6789aec3b565b2761b250332efcc637fa5129a0c72c95d7a070 · sha256:c114388c8fdff25b… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-22","description":"CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d7411c1fb405c6789aec3b565b2761b250332efcc637fa5129a0c72c95d7a070 · sha256:c114388c8fdff25b… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"name":"https://github.com/Pennyw0rth/NetExec/commit/7d027f2774d0520b322d60f9c99b9ab3edb4035e","tags":["x_refsource_MISC"],"url":"https://github.com/Pennyw0rth/NetExec/commit/7d027f2774d0520b322d60f9c99b9ab3edb4035e"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d7411c1fb405c6789aec3b565b2761b250332efcc637fa5129a0c72c95d7a070 · sha256:c114388c8fdff25b… · /containers/cna/references/3
{"name":"https://github.com/Pennyw0rth/NetExec/issues/1120","tags":["x_refsource_MISC"],"url":"https://github.com/Pennyw0rth/NetExec/issues/1120"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d7411c1fb405c6789aec3b565b2761b250332efcc637fa5129a0c72c95d7a070 · sha256:c114388c8fdff25b… · /containers/cna/references/1
{"name":"https://github.com/Pennyw0rth/NetExec/pull/1121","tags":["x_refsource_MISC"],"url":"https://github.com/Pennyw0rth/NetExec/pull/1121"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d7411c1fb405c6789aec3b565b2761b250332efcc637fa5129a0c72c95d7a070 · sha256:c114388c8fdff25b… · /containers/cna/references/2
{"name":"https://github.com/Pennyw0rth/NetExec/security/advisories/GHSA-fccr-6qm2-7h27","tags":["x_refsource_CONFIRM"],"url":"https://github.com/Pennyw0rth/NetExec/security/advisories/GHSA-fccr-6qm2-7h27"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d7411c1fb405c6789aec3b565b2761b250332efcc637fa5129a0c72c95d7a070 · sha256:c114388c8fdff25b… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.