CVE-2026-40258Disclosure

LOWCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Gramps Web API is a Python REST API for the genealogical research software Gramps. Versions 1.6.0 through 3.11.0 have a path traversal vulnerability (Zip Slip) in the media archive import feature. An authenticated user with owner-level privileges can craft a malicious ZIP file with directory-traversal filenames to write arbitrary files outside the intended temporary extraction directory on the server's local filesystem. Startig in version 3.11.1, ZIP entry names are now validated against the resolved real path of the temporary directory before extraction. Any entry whose resolved path falls outside the temporary directory raises an error and aborts the import.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-11); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-11: 1Mentions · 2026-04-17: 1Mentions · 2026-04-18: 1PoC Mentioned / Linked · 2026-04-11: 1Technical Details · 2026-04-11: 1Technical Details · 2026-04-17: 1Technical Details · 2026-04-18: 104-1104-1704-18
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-40258 The Gramps Web API is a Python REST API for the genealogical research software Gramps. Versions 1.6.0 through 3.11.0 have a path traversal vulnerability (Zip Slip) in… https://www.cve.org/CVERecord?id=CVE-2026-40258

    Post summary

    CVE-2026-40258 identifies a path traversal flaw (Zip Slip) in the Gramps Web API across versions 1.6.0 to 3.11.0.

    00000117
    57.2K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-40258: Gramps Web API has Zip Slip Path... Zip Slip with owner privs = full filesystem write access - genealogy apps handling user archives are prime targets for ... https://zerodaysignal.com/vulnerability/CVE-2026-40258 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A brief disclosure notes a Zip Slip path traversal in Gramps Web API, granting full filesystem write with owner privileges.

    0000067
    218 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A Zip Slip path traversal flaw in `gramps-webapi` (CVE-2026-40258) could allow arbitrary file writes. Evaluate your `gramps-webapi` deployments for this #PathTraversal #grampswebapi #infosec vulnerability. https://www.pulsepatch.io/posts/cve-2026-40258-gramps-webapi-zip-slip-path-traversal

    Post summary

    A Zip Slip path traversal flaw in gramps-webapi (CVE-2026-40258) may allow arbitrary file writes; users are advised to assess and mitigate the vulnerability.

    0000059
    11 followersView on X

Explore more