Newell Brands DYMO ID 1.5.1.71 resolves its plugin Modules directory relative to the process working directory. An attacker could store a job file alongside malicious modules / DLL that sets the process working directory to the job file's folder when a victim clicks on the file, resulting in code execution at the victim's privilege level. Fixed in 1.6.0.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 05 Oct 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Newell Brands DYMO ID 1.5.1.71 resolves its plugin Modules directory relative to the process working directory. An attacker could store a job file alongside malicious modules / DLL that sets the process working directory to the job file's folder when a victim clicks on the file, resulting in code execution at the victim's privilege level. Fixed in 1.6.0. | |
| Title | Newell Brands DYMO ID parent directory open to path traversal through improper spheres of control | |
| Weaknesses | CWE-22 CWE-668 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2026-10-05T20:37:26.019Z
Reserved: 2026-09-28T20:09:51.956Z
Link: CVE-2026-102262
No data.
Status : Received
Published: 2026-10-05T21:16:32.400
Modified: 2026-10-05T21:16:32.400
Link: CVE-2026-102262
No data.
OpenCVE Enrichment
Updated: 2026-10-05T22:30:19Z