CVE-2026-45380 | rikyoz bit7z up to 4.0.11 restoreSymlink path traversal (GHSA-8wj8-9jwv-j24v)
A vulnerability identified as critical has been detected in rikyoz bit7z up to 4.0.11. This affects the function SafeOutPathBuilder::restoreSymlink. Performing a manipulation results in path traversal.
This vulnerability was named CVE-2026-45380. The attack needs to be approached locally. There is no available exploit.
You should upgrade the affected component.