Executive brief
DigiDoc4 is a desktop application used for digital signing and encryption of documents in Estonia. A path traversal vulnerability allows attackers to access files outside the intended restricted directory, potentially exposing sensitive documents or system files that could be manipulated or read without proper authorization.
Technical details
This is a path traversal vulnerability (CWE-22) in the DigiDoc4 client, affecting versions 4.0.0 through before 4.11.0. The vulnerability stems from improper validation of file paths, likely in the temporary file handling mechanism based on the cleanup of temp file handling in the fix. An attacker with local access or ability to influence file paths could craft malicious input to traverse the directory structure and access files outside the intended restricted directory. The vulnerability was patched in version 4.11.0, with fixes merged in July 2026.
Affected products
- Estonian Information System Authority DigiDoc4 4.0.0 to before 4.11.0
Timeline
- 2026-08-20: disclosed
- 2026-07-03: patched: Fix merged in pull request #1402