CVE-2023-26266

In AFL++ 4.05c, the CmpLog component uses the current working directory to resolve and execute unprefixed fuzzing targets, allowing code execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:afl\+\+_project:afl\+\+:4.05c:*:*:*:*:*:*:*

History

14 Mar 2025, 19:15

Type Values Removed Values Added
CWE CWE-427

Information

Published : 2023-02-21 04:15

Updated : 2025-03-14 19:15


NVD link : CVE-2023-26266

Mitre link : CVE-2023-26266

CVE.ORG link : CVE-2023-26266


JSON object : View

Products Affected

afl\+\+_project

  • afl\+\+
CWE
NVD-CWE-noinfo CWE-427

Uncontrolled Search Path Element