CVE-2026-32805Disclosure(ctfer-io / romeo)

LOWCVSS 7.5 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for functional and integration tests within GitHub Actions. Prior to version 0.2.2, the `sanitizeArchivePath` function in `webserver/api/v1/decoder.go` (lines 80-88) is vulnerable to a path traversal bypass due to a missing trailing path separator in the `strings.HasPrefix` check. A crafted tar archive can write files outside the intended destination directory. Version 0.2.2 fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • romeo

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
romeo

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-19: 4Technical Details · 2026-03-19: 303-19
Signal classification1 categories
Disclosure
4100.0%
Referenced assets3 URLs
Full discourse4 posts
  • NerdieNews@NewsNerdie
    Disclosure

    Top cybersecurity news: CVE-2026-32255: Kan project management tool versions 0.5.4 and below are vulnerable to unauthenticated SSRF via the attachment download endpoint, posing significant security risks. CVE-2026-32805: Romeo's archive sanitization process is susceptible to path traversal due to missing checks, potentially allowing unauthorized access. CVE-2025-55040: MuraCMS faces a CSRF vulnerability, enabling attackers to upload malicious form definitions without user consent. CVE-2026-32000: OpenClaw versions before 2026.2.19 are vulnerable to command injection via the Lobster tool, exposing systems to potential shell metacharacter attacks. Stay sharp. Stay secure. #NerdieNews #CyberSecurity #InfoSec #ZeroDay #PatchTuesday

    Post summary

    The post announces four newly disclosed CVEs affecting various software. It highlights the specific vulnerability types and affected versions but does not provide patches, exploit code, or evidence of active exploitation.

    0000036
    49 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32805 Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for functional and integration tests within GitHub Actions… https://www.cve.org/CVERecord?id=CVE-2026-32805

    Post summary

    The post announces CVE‑2026‑32805, a vulnerability related to the Romeo tool’s code‑coverage feature for Go 1.20 applications in GitHub Actions, but provides only a brief disclosure without technical or exploit details.

    00000123
    56.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32805 Path Traversal Vulnerability in Romeo Go Code Coverage Tool Before 0.2.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32805

    Post summary

    CVE‑2026‑32805 discloses a path traversal flaw affecting Romeo Go Code Coverage Tool versions prior to 0.2.2, as documented on Vulmon.

    0000031
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-32805 - Romeo is vulnerable to Archive Slip due to missing checks in sanitization Intel Report: https://ift.tt/i30jNCv

    Post summary

    The alert announces CVE-2026-32805, a Romeo vulnerability that allows Archive Slip due to inadequate sanitization, without providing PoC, exploit, patch, or active exploitation information.

    0000040
    335 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appctfer-ioromeo---

Explore more