CVE-2026-37531Disclosure(linuxfoundation / automotive_grade_linux)

LOWCVSS 9.8 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367) in the widget installation flow. The is_valid_filename function in wgtpkg-zip.c validates ZIP entry names but does not check for dot notation directory traversal sequences it only blocks absolute paths. The zread extraction function uses openat(workdirfd, filename, O_CREAT) which resolves dot notation values relative to the work directory, allowing files to be written anywhere on the filesystem. Critically, in function install_widget in file wgtpkg-install.c, extraction via zread occurs BEFORE signature verification via check_all_signatures. Even if signature verification fails, the error cleanup (remove_workdir) only deletes the temporary work directory files written outside via path traversal persist permanently.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-367

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • automotive_grade_linux

Threat summary

  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-05-12)
  • 6 total mentions across 2 days

Affected systems

Products
automotive_grade_linux

Deep dive

Activity timeline6 mentions / 2d
01234Mentions · 2026-05-01: 2Mentions · 2026-05-12: 4Technical Details · 2026-05-01: 2Technical Details · 2026-05-12: 305-0105-12
Signal classification2 categories
Disclosure
466.7%
General
233.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-012
Disclosure2
2026-05-124
Disclosure2General2
Full discourse6 posts
  • Lyrie.ai@lyrie_ai
    General

    --- Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation. CVE: CVE-2026-37531 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The advisory lists CVE-2026-37531 as a critical vulnerability with a CVSS of 9.8, but offers no PoC, exploit, or remediation information.

    1000035
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-37531 (CVSS 9.8) — multiple products. CVE: CVE-2026-37531 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces a critical vulnerability (CVE-2026-37531) with a CVSS of 9.8, affecting multiple products, but provides no PoC, exploit, patch, or evidence of active exploitation.

    1000023
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-37531 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367)…

    Post summary

    The advisory announces a critical zip‑slip path traversal vulnerability combined with a TOCTOU race condition in AGL app‑framework‑main 17.1.12, providing detailed CVE and CVSS information.

    1000049
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-37531-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided text only references a link to an advisory for CVE‑2026‑37531; it offers no explicit information about PoC, exploitation, patches, or technical vulnerability details.

    0000020
    210 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-37531 Zip Slip Path Traversal and TOCTOU Race Condition in AGL app-framework-main 17.1.12 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-37531

    Post summary

    The post announces CVE-2026-37531, identifying a Zip Slip path traversal and a TOCTOU race condition in the AGL app-framework, but provides no PoC, exploit, patch, or evidence of active exploitation.

    0000054
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-37531 AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367) in the widget installati… https://www.cve.org/CVERecord?id=CVE-2026-37531

    Post summary

    The statement announces CVE-2026-37531 as a Zip Slip path traversal coupled with a TOCTOU race condition in AGL app-framework-main, providing vulnerability details but no PoC, exploit, patch, or evidence of active exploitation.

    00000139
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxfoundationautomotive_grade_linux---

Explore more