Path traversal in restore handler in Collibra Agent, allows an attacker to write arbitrary files via a crafted ZIP archive. Collibra Agent fails to properly validate and canonicalize file path during ZIP extraction, this can allow an attacker to write files outside the intended extraction directory.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
Collibra Agent contains a path traversal vulnerability in its restore handler that allows attackers to write arbitrary files to systems by crafting malicious ZIP archives. The vulnerability stems from improper validation and canonicalization of file paths during ZIP extraction, enabling an attacker to use directory traversal sequences (such as "../") to escape the intended extraction directory and place files anywhere on the filesystem with the privileges of the Agent process. This affects organizations using Collibra for data governance and metadata management, potentially compromising system integrity, enabling code execution, or exposing sensitive data depending on where files are written.
While Casky.ai currently shows zero mapped skills for this specific CVE, practitioners using the platform would benefit from extended reasoning analysis focused on MITRE ATT&CK techniques like T1566 (Phishing - malicious attachment delivery), T1204 (User Execution), and T1547 (Boot or Logon Autostart Execution) when analyzing attack chains involving malicious ZIP files. Security teams investigating Collibra environments should enable file integrity monitoring and input validation controls, then query Casky for skills related to archive extraction abuse, file write anomalies, and privilege escalation patterns. As threat actors refine their exploitation techniques, new defensive skills mapping to path traversal and ZIP-based attacks would enhance detection of both initial compromise attempts and post-exploitation file placement activities commonly observed in APT campaigns.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-10621. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation