
🐛 CVE-2026-35465 – SecureDrop Client path traversal code exec (High): Compromised SecureDrop Server exploits bad gzip filename validation for absolute paths, overwriting SQLite DB or achieving code exec on client VM (sd-app) despite Tor hardening. Update to 0.17.5. https://nvd.nist.gov/vuln/detail/CVE-2026-35465
Post summary
The tweet announces a new CVE-2026-35465 affecting SecureDrop Client, details the path traversal flaw and its impact, and advises updating to version 0.17.5.


