CVE-2026-57079: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in SANKO Net::BitTorrent
Net::BitTorrent versions before 2.1.0 for Perl write files outside the download directory via path traversal in peer-supplied metadata. Net::BitTorrent validates file path components only on the .torrent-file ingest path. The peer and magnet metadata path (_on_metadata_received, reached from the BEP09 ut_metadata extension) passes attacker-supplied file names straight to Storage::add_file and Storage::_parse_file_tree, where Path::Tiny's child() does not collapse "..". A v2 file tree key, a v1 files[].path element, or a single-file name containing ".." segments therefore resolves outside the download directory. Because the peer also controls the piece hashes and the served bytes, content verification passes, so a malicious magnet or peer writes attacker-chosen content to an attacker-chosen path on the downloading host.
AI Analysis
Technical Summary
Net::BitTorrent versions <=2.0.1 for Perl improperly limit pathname traversal in peer-supplied metadata, specifically in the handling of file paths received from peers or magnet links via the BEP09 ut_metadata extension. The software validates file path components only during .torrent-file ingestion but fails to sanitize paths in peer metadata, allowing ".." segments to escape the download directory. Because the peer controls piece hashes and served bytes, the content verification passes, enabling an attacker to write arbitrary files outside the intended directory.
Potential Impact
An attacker can write files to arbitrary locations outside the designated download directory on the victim's system by supplying crafted metadata with path traversal sequences. This could lead to unauthorized file creation or overwriting, potentially impacting system integrity or security depending on the file paths targeted. The vulnerability does not affect confidentiality or availability directly and requires no privileges or user interaction to exploit.
Mitigation Recommendations
No official patch or remediation level is currently documented. Users should upgrade to Net::BitTorrent version 2.1.0 or later where this issue is fixed. Until then, avoid using untrusted peers or magnet links and consider restricting file system permissions to limit the impact of unauthorized file writes. Monitor vendor advisories for updates on official fixes.
CVE-2026-57079: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in SANKO Net::BitTorrent
Description
Net::BitTorrent versions before 2.1.0 for Perl write files outside the download directory via path traversal in peer-supplied metadata. Net::BitTorrent validates file path components only on the .torrent-file ingest path. The peer and magnet metadata path (_on_metadata_received, reached from the BEP09 ut_metadata extension) passes attacker-supplied file names straight to Storage::add_file and Storage::_parse_file_tree, where Path::Tiny's child() does not collapse "..". A v2 file tree key, a v1 files[].path element, or a single-file name containing ".." segments therefore resolves outside the download directory. Because the peer also controls the piece hashes and the served bytes, content verification passes, so a malicious magnet or peer writes attacker-chosen content to an attacker-chosen path on the downloading host.
CVSS v3.1
Score 5.3medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Net::BitTorrent versions <=2.0.1 for Perl improperly limit pathname traversal in peer-supplied metadata, specifically in the handling of file paths received from peers or magnet links via the BEP09 ut_metadata extension. The software validates file path components only during .torrent-file ingestion but fails to sanitize paths in peer metadata, allowing ".." segments to escape the download directory. Because the peer controls piece hashes and served bytes, the content verification passes, enabling an attacker to write arbitrary files outside the intended directory.
Potential Impact
An attacker can write files to arbitrary locations outside the designated download directory on the victim's system by supplying crafted metadata with path traversal sequences. This could lead to unauthorized file creation or overwriting, potentially impacting system integrity or security depending on the file paths targeted. The vulnerability does not affect confidentiality or availability directly and requires no privileges or user interaction to exploit.
Mitigation Recommendations
No official patch or remediation level is currently documented. Users should upgrade to Net::BitTorrent version 2.1.0 or later where this issue is fixed. Until then, avoid using untrusted peers or magnet links and consider restricting file system permissions to limit the impact of unauthorized file writes. Monitor vendor advisories for updates on official fixes.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CPANSec
- Date Reserved
- 2026-06-23T18:20:33.513Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a43addd27e9c79719af4978
Added to database: 06/30/2026, 11:51:57 UTC
Last enriched: 07/20/2026, 18:07:48 UTC
Last updated: 08/13/2026, 12:41:11 UTC
Views: 127
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.