CVE-2026-37531CRITICAL 9.8EPSS p48.7%

CVE-2026-37531CVE-2026-37531

Description

AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367) in the widget installation flow. The is_valid_filename function in wgtpkg-zip.c validates ZIP entry names but does not check for dot notation directory traversal sequences it only blocks absolute paths. The zread extraction function uses openat(workdirfd, filename, O_CREAT) which resolves dot notation values relative to the work directory, allowing files to be written anywhere on the filesystem. Critically, in function install_widget in file wgtpkg-install.c, extraction via zread occurs BEFORE signature verification via check_all_signatures. Even if signature verification fails, the error cleanup (remove_workdir) only deletes the temporary work directory files written outside via path traversal persist permanently.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.71% probability of exploitation · percentile 48.7% · 2026-06-19T12:03:05Z
Published2026-05-01
Last modified2026-05-18

Underlying weaknesses· 2

CWE-22CWE-367

References

  1. https://gerrit.automotivelinux.org/gerrit/src/app-framework-main
  2. https://gist.github.com/sgInnora/8526eedcfd826d05ef1fc45d8f405643

2

TypeTargetConfidenceTier
WeaknessImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')cwe-220%live
WeaknessTime-of-check Time-of-use (TOCTOU) Race Conditioncwe-3670%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-0851
CVE
CVE-2025-7039
CVE
CVE-2025-3115
CVE
CVE-2026-52752
CVE
CVE-2026-26157
CVE
CVE-2025-41735
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.