CVE-2023-52076
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path traversal and arbitrary file write vulnerability exists in versions of Atril prior to 1.26.2. This vulnerability is capable of writing arbitrary files anywhere on the filesystem to which the user opening a crafted document has access. The only limitation is that this vulnerability cannot be exploited to overwrite existing files, but that doesn't stop an attacker from achieving Remote Command Execution on the target system. Version 1.26.2 of Atril contains a patch for this vulnerability.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.5
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
- EPSS probability
- 11.35%
- CWE
- CWE-24, CWE-25, CWE-27, CWE-22
- Published
- 2024-01-25
- Last modified
- 2026-03-13
Affected products
- mate-desktop atril
Weakness type
Related vulnerabilities
- CVE-2025-27920 — Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By us
- CVE-2024-6746 — NaiboWang EasySpider HTTP GET Request server.js path traversal
- CVE-2026-39813 — A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.
- CVE-2025-53513 — Zip slip vulnerability in Juju
- CVE-2024-23657 — Path Traversal: '../filedir' in Nuxt Devtools
- CVE-2021-26725 — Authenticated command path traversal on timezone settings in Guardian/CMC before 20.0.7.4
- CVE-2025-60344 — A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attacker
- CVE-2023-1800 — sjqzhang go-fastdfs File Upload uploa upload path traversal