# CVE-2026-45384

## Summary

- **CVE ID:** CVE-2026-45384
- **Severity:** MEDIUM
- **CVSS Score:** 6.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L)
- **CWE:** CWE-59, CWE-377
- **Published:** Jun 10, 2026
- **Last Modified:** Jun 11, 2026

## Description

bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4.0.12, there is an arbitrary file overwrite vulnerability via symlink attack on predictable temp files during archive update. This issue has been patched in version 4.0.12.

## Affected Products

- rikyoz — bit7z (< 4.0.12)

## References

- [CNA](https://github.com/rikyoz/bit7z/security/advisories/GHSA-wjch-42rm-q53h)
- [CNA](https://github.com/rikyoz/bit7z/releases/tag/v4.0.12)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.13%
- **EPSS Percentile:** 2.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._