CVE-2026-47121: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in sparkle-project Sparkle
CVE-2026-47121 is a path traversal vulnerability in the Sparkle software update framework for macOS. Versions prior to 2.9.2 do not properly detect symbolic links deeper in relative paths during delta archive extraction, allowing an attacker with a compromised EdDSA signing key to write arbitrary files at the root level. The vulnerability requires a maliciously crafted .delta file that passes signature verification. Version 2.9.2 includes a patch addressing this issue.
AI Analysis
Technical Summary
Sparkle versions before 2.9.2 contain a path traversal vulnerability (CWE-22) in the delta update extraction process. The code checks for '..' in relative paths and rejects writes if the immediate parent directory is a symlink, but it fails to detect symlinks deeper in the path. The extractItem: function creates symlinks from archive content without validating the symlink target, enabling escape from the intended destination directory during file writes. Exploitation requires a malicious .delta file that passes EdDSA signature verification, implying compromise of the signing private key. When the AppInstaller runs as root for system-domain installs, this allows arbitrary root-level file writes beyond normal bundle replacement. The issue is patched in Sparkle version 2.9.2.
Potential Impact
An attacker with access to the EdDSA private signing key can craft a malicious update (.delta) that exploits this vulnerability to write arbitrary files at the root level on macOS systems where Sparkle is used for system-domain installs. This elevates the attacker's capabilities beyond normal update replacement, potentially enabling full system compromise. There is no indication of known exploits in the wild.
Mitigation Recommendations
Upgrade to Sparkle version 2.9.2 or later, which contains a patch for this path traversal vulnerability. Since the vulnerability requires a compromised EdDSA signing key to exploit, protecting the signing keys is critical. No other mitigations are indicated.
CVE-2026-47121: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in sparkle-project Sparkle
Description
CVE-2026-47121 is a path traversal vulnerability in the Sparkle software update framework for macOS. Versions prior to 2.9.2 do not properly detect symbolic links deeper in relative paths during delta archive extraction, allowing an attacker with a compromised EdDSA signing key to write arbitrary files at the root level. The vulnerability requires a maliciously crafted .delta file that passes signature verification. Version 2.9.2 includes a patch addressing this issue.
CVSS v3.1
Score 6.1medium
Affected software
pkg:github/sparkle-project/SparkleRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Sparkle versions before 2.9.2 contain a path traversal vulnerability (CWE-22) in the delta update extraction process. The code checks for '..' in relative paths and rejects writes if the immediate parent directory is a symlink, but it fails to detect symlinks deeper in the path. The extractItem: function creates symlinks from archive content without validating the symlink target, enabling escape from the intended destination directory during file writes. Exploitation requires a malicious .delta file that passes EdDSA signature verification, implying compromise of the signing private key. When the AppInstaller runs as root for system-domain installs, this allows arbitrary root-level file writes beyond normal bundle replacement. The issue is patched in Sparkle version 2.9.2.
Potential Impact
An attacker with access to the EdDSA private signing key can craft a malicious update (.delta) that exploits this vulnerability to write arbitrary files at the root level on macOS systems where Sparkle is used for system-domain installs. This elevates the attacker's capabilities beyond normal update replacement, potentially enabling full system compromise. There is no indication of known exploits in the wild.
Mitigation Recommendations
Upgrade to Sparkle version 2.9.2 or later, which contains a patch for this path traversal vulnerability. Since the vulnerability requires a compromised EdDSA signing key to exploit, protecting the signing keys is critical. No other mitigations are indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-18T19:50:18.694Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a5f7ac92a4a8d598939c04a
Added to database: 07/21/2026, 13:57:29 UTC
Last enriched: 07/21/2026, 14:12:10 UTC
Last updated: 07/21/2026, 16:21:35 UTC
Views: 42
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.