CVE-2026-41958
MEDIUM
NVD
CVSS Score
6.5
Severity
MEDIUM
Published
Oct 07, 2026
Vendor
unknown
Description
A path traversal vulnerability exists in the unzip_http RemoteZipFile extract functionality of VisiData (version(s): dev (commit 38b21f78)). A specially crafted .zip file can lead to arbitrary file write. An attacker can provide a crafted URL to trigger this vulnerability.