Path traversal in Cryptomator - CVE-2026-32310
Published: April 20, 2026
Cryptomator
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to path traversal in the masterkeyfile loader when processing an unverified vault configuration during the unlock flow. A remote user can supply a crafted masterkeyfile key identifier that resolves to a local or UNC path to disclose sensitive information.
User interaction is required to open or unlock a malicious vault, and on Windows a UNC path can trigger outbound SMB access before the passphrase is entered.