CVE-2026-32116Disclosure(magic-wormhole_project / magic_wormhole)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. From 0.21.0 to before 0.23.0, receiving a file (wormhole receive) from a malicious party could result in overwriting critical local files, including ~/.ssh/authorized_keys and .bashrc. This could be used to compromise the receiver's computer. Only the sender of the file (the party who runs wormhole send) can mount the attack. Other parties (including the transit/relay servers) are excluded by the wormhole protocol. This vulnerability is fixed in 0.23.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • magic_wormhole

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-12); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
magic_wormhole

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-12: 1Mentions · 2026-03-13: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 103-1203-13
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-121
Disclosure1
2026-03-131
General1
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-32116 File Overwrite Vulnerability in Magic Wormhole Versions 0.21.0 to... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32116 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet only references CVE-2026-32116, pointing to a vulnerability details page for a file overwrite problem in Magic Wormhole, without providing further exploit or remediation information.

    0102090
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32116 Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. From 0.21.0 to before 0.23.0, receiving a file (wormhole r… https://www.cve.org/CVERecord?id=CVE-2026-32116

    Post summary

    The text announces a new vulnerability (CVE‑2026‑32116) in Magic Wormhole, where a bug in versions 0.21.0 through 0.22.x enables arbitrary‑sized file transfers between computers.

    00000152
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmagic-wormhole_projectmagic_wormhole-python-

Explore more