CVE-2026-32310 | cryptomator up to 1.19.0 Masterkeyfile Loader keyId.getSchemeSpecificPart path traversal (GHSA-5phc-5pfx-hr52)
A vulnerability was found in cryptomator up to 1.19.0. It has been rated as critical. This vulnerability affects the function keyId.getSchemeSpecificPart of the component Masterkeyfile Loader. This manipulation causes path traversal.
This vulnerability is registered as CVE-2026-32310. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.