Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB. This issue affects OpenRGB through 1.0rc3.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-59682 is a critical arbitrary file overwrite vulnerability (CVSS 9.1) affecting OpenRGB through version 1.0rc3, stemming from improper input validation in the SAVE_PROFILE message handler (CWE-73: External Control of File Name or Path). An attacker can exploit this flaw to overwrite arbitrary files on a system running vulnerable OpenRGB instances, potentially leading to code execution, configuration tampering, or denial of service. This affects users of OpenRGB—a popular open-source RGB lighting control application—across Windows, Linux, and macOS platforms. The vulnerability is particularly concerning because OpenRGB often runs with elevated privileges to access hardware devices, amplifying the impact of successful exploitation.
While no MITRE ATT&CK techniques are formally mapped to this CVE, Casky's Claude AI-powered analysis would flag this as consistent with Execution and Persistence attack patterns: specifically File and Directory Permissions Modification (T1222) if the overwrite alters access controls, and Implant Internal Image (T1525) if malicious profiles are persisted. Practitioners monitoring their Casky skill findings would observe anomalous SAVE_PROFILE message patterns—including suspicious file path parameters containing directory traversal sequences (../) or absolute paths pointing outside expected profile directories—combined with file system write events to critical system or application directories. The platform's extended reasoning would correlate these signals to surface the root cause: insufficient path sanitization before file write operations, enabling an unauthenticated or low-privileged attacker to redirect profile saves to arbitrary locations.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-59682. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation