Executive brief
The Sleuth Kit is a collection of command-line tools used by digital forensics investigators to analyze disk images and recover files. A vulnerability in the 'tsk_recover' tool allows a malicious disk image to write files to unintended locations on the investigator's computer. This could allow an attacker to gain control of the system by overwriting critical startup files or configuration settings when the investigator attempts to process the evidence.
Technical details
A path traversal vulnerability (CWE-22) exists in the tsk_recover utility of The Sleuth Kit through version 4.14.0. The root cause is insufficient sanitization of filenames and directory paths within a processed filesystem image. An attacker can craft a malicious image containing filenames with '../' sequences; when tsk_recover processes this image, it may write files to arbitrary locations on the host filesystem. This can lead to local code execution if the attacker overwrites sensitive files such as .bashrc or cron entries. Exploitation requires the victim to run tsk_recover on a malicious image. A fix is available in the project's source repository (commit a3f96b3).
Affected products
- Sleuth Kit The Sleuth Kit through 4.14.0
Timeline
- 2026-03-05: disclosed: Initial discovery by Mobasi Sentinel program
- 2026-04-08: advisory: NVD and VulnCheck publication
- 2026-04-08: patched: Fix identified in GitHub commit a3f96b3bc36a8bb1a00c297f77110d4a6e7dd31b