CVE-2026-32731 is a path traversal (Zip Slip) vulnerability in ApostropheCMS prior to @apostrophecms/import-export version 3.5.3. The vulnerable code is the extract() function in gzip.js, which creates output files using fs.createWriteStream(path.join(exportPath, header.name)). Because path.join() does not neutralize traversal components such as ../, a crafted tar entry name like ../../evil.js can cause extraction outside the intended exportPath directory. The implementation does not perform a canonical path validation or containment check before opening the write stream. As a result, an attacker can supply a malicious .tar.gz archive through the CMS import workflow and cause attacker-controlled files to be written to arbitrary filesystem locations accessible to the Node.js process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a minimal proof-of-concept for CVE-2026-32731 consisting of two files: a short README and a single Python script, exp.py. The script is the sole exploit component and acts as an archive generator rather than a network-delivered exploit. It takes two command-line arguments: a local payload file and a target path. It reads the payload bytes from disk, then creates a gzip-compressed tar archive named evil-slip.tar.gz. Inside the archive it places two small JSON files, aposDocs.json and aposAttachments.json, both containing empty arrays, likely to mimic the structure expected by a vulnerable import routine. It then adds a third tar member whose filename is exactly the attacker-supplied target_path and whose contents are the payload bytes. The core capability is a tar-slip/path-traversal arbitrary file write during extraction by a vulnerable application that fails to sanitize archive entry paths. There are no hardcoded network endpoints, callbacks, shells, or post-exploitation actions. The exploit does not itself attack a remote service; instead, it prepares a malicious archive for later delivery to a vulnerable import/extraction feature. The repository is small, straightforward, and clearly intended as a POC demonstrating archive path traversal and file overwrite impact.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.