LiveActive security incident?Get immediate response
CVE Record

CVE-2021-34422: Path traversal of file names in Keybase Client for Windows

The Keybase Client for Windows before version 5.7.0 contains a path traversal vulnerability when checking the name of a file uploaded to a team folder. A malicious user could upload a file to a shared folder with a specially crafted file name which could allow a user to execute an application which was not intended on their host machine. If a malicious user leveraged this issue with the public folder sharing feature of the Keybase client, this could lead to remote code execution.

HighCVSS 7.2Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

Keybase for Windows versions before 5.7.0 could mishandle a malicious filename in shared folders. In the wrong sharing setup, this could make a victim’s machine run an unintended application. The concern is highest where Keybase public or team folder sharing was used on Windows endpoints.

Executive priority

Prioritize remediation where Keybase for Windows was deployed, especially on systems using shared folders. The vulnerability has credible high-severity impact, but the provided evidence does not show known active exploitation.

Technical view

The flaw is a path traversal issue in filename checks for files uploaded to Keybase team folders on Windows. A crafted filename could lead to unintended application execution. The CVE lists potential remote code execution through public folder sharing. CVSS 3.1 is 7.2 with network attack vector, low complexity, and changed scope.

Likely exposure

Exposure is limited to Keybase Client for Windows before version 5.7.0. Organizations that did not deploy Keybase, only used non-Windows clients, or upgraded beyond 5.7.0 are less likely to be affected based on the provided sources.

Exploitation context

The provided sources do not report active exploitation, and this CVE is not marked KEV. The described scenario requires a malicious uploaded filename in a shared folder; public folder sharing could broaden impact to remote code execution.

Researcher notes

The source bundle names no CWE and gives limited implementation detail. Validate exposure by version and feature use rather than by exploit testing. Avoid assuming non-Windows impact or specific file paths because those details are not present in the sources.

Mitigation direction

  • Upgrade Keybase Client for Windows to version 5.7.0 or later.
  • Review Zoom or Keybase security guidance for any additional vendor instructions.
  • Limit use of public folder sharing where legacy clients may remain.
  • Prioritize remediation on Windows endpoints using Keybase team folders.

Validation and detection

  • Inventory endpoints with Keybase Client for Windows installed.
  • Confirm installed Keybase versions are 5.7.0 or later.
  • Identify business units using Keybase team or public folder sharing.
  • Review endpoint telemetry for unexpected application launches associated with Keybase activity.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

description · low confidence lookup

Execution behavior lookup

The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
description · low confidence lookup

File access behavior lookup

The CVE wording references file access or upload behavior, so file telemetry and web shell review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2021-34422 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
7.2 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
7.2CVSS 3.1HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N3.92.7Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

7.2High
CVSS 3.1 vector shape for CVE-2021-34422Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Zoom Video Communications IncKeybase Client for WindowsunspecifiedListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.