CVE-2026-35465Disclosure(freedom / securedrop-client)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch freedom securedrop-client systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. In versions 0.17.4 and below, a compromised SecureDrop Server can achieve code execution on the Client's virtual machine (sd-app) by exploiting improper filename validation in gzip archive extraction, which permits absolute paths and enables overwriting critical files like the SQLite database. Exploitation requires prior compromise of the dedicated SecureDrop Server, which itself is hardened and only accessible via Tor hidden services. Despite the high attack complexity, the vulnerability is rated High severity due to its significant impact on confidentiality, integrity, and availability of decrypted source submissions. This issue is similar to CVE-2025-24888 but occurs through a different code path, and a more robust fix has been implemented in the replacement SecureDrop Inbox codebase. The issue has been fixed in version 0.17.5.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-36CWE-73

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • securedrop-client

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-18); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
securedrop-client

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-18: 2Mentions · 2026-04-19: 1Patch / Workaround · 2026-04-19: 1Technical Details · 2026-04-18: 1Technical Details · 2026-04-19: 104-1804-19
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-182
Disclosure1General1
2026-04-191
Disclosure1
Full discourse3 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    🐛 CVE-2026-35465 – SecureDrop Client path traversal code exec (High): Compromised SecureDrop Server exploits bad gzip filename validation for absolute paths, overwriting SQLite DB or achieving code exec on client VM (sd-app) despite Tor hardening. Update to 0.17.5. https://nvd.nist.gov/vuln/detail/CVE-2026-35465

    Post summary

    The tweet announces a new CVE-2026-35465 affecting SecureDrop Client, details the path traversal flaw and its impact, and advises updating to version 0.17.5.

    1000045
    1.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-35465 SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. In versions 0.17.4 and b… https://www.cve.org/CVERecord?id=CVE-2026-35465

    Post summary

    The brief notice only references CVE‑2026‑35465 for the SecureDrop Client without providing any further technical, exploit, or patch information.

    0000082
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-35465 Remote Code Execution in SecureDrop Client via Improper Gzip Archive Path Validation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-35465

    Post summary

    The post references CVE-2026-35465, noting an RCE flaw in SecureDrop client caused by improper gzip path validation, but provides no PoC, exploit, patch, or active exploitation evidence.

    0000036
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfreedomsecuredrop-client---

Explore more