
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2016-20038 is a stack-based buffer overflow vulnerability in yTree version 1.94-1.1, a file manager utility for Unix-like systems. It allows local attackers to execute arbitrary code by supplying an excessively long command-line argument to the application. The vulnerability was assigned a CVSS v3.1 base score of 8.4 (High) and a CVSS v4.0 base score of 8.6 (High). Despite the CVE identifier referencing 2016, the vulnerability was formally published in March 2026 (VulnCheck Advisory, EUVD).
The root cause is an out-of-bounds write (CWE-787) resulting from insufficient bounds checking on command-line argument input. When a user or script passes an excessively long argument to the yTree binary, the application writes beyond the allocated stack buffer, overwriting the return address and enabling arbitrary code execution. An attacker can craft a malicious argument containing shellcode and a controlled return address to redirect execution flow. A public proof-of-concept exploit is available on Exploit-DB (ID 39406) (Exploit-DB, VulnCheck Advisory).
Successful exploitation allows a local attacker to execute arbitrary code in the context of the yTree process, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker who can run the yTree binary with a crafted argument could gain code execution, potentially escalating privileges or pivoting to other local resources depending on the system configuration. The scope is limited to the local system, with no direct network-based exploitation path (VulnCheck Advisory).
A public proof-of-concept exploit has been available on Exploit-DB (entry 39406) since at least 2016, predating the formal CVE assignment (Exploit-DB). The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of active exploitation in the wild. There is no evidence of in-the-wild exploitation, threat actor attribution, or inclusion in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection coverage exists via Tenable Nessus plugin 304204 (Tenable Nessus).
ytree <crafted_argument> where <crafted_argument> is the malicious string, triggering the stack buffer overflow.ytree binary (e.g., /bin/sh, /bin/bash) with unusual arguments or no controlling terminal.ytree execution with abnormally long argument strings or segmentation faults in application logs./tmp) created around the time of ytree execution, potentially indicating dropped payloads or scripts.No vendor patch has been publicly released for yTree 1.94-1.1 as of the time of publication. Users should consider removing or restricting access to the yTree binary if it is not required, using filesystem permissions or access controls to limit who can execute it. Enabling stack protection mechanisms (e.g., ASLR, stack canaries via compiler flags) at the OS level can reduce exploitability. Organizations should monitor for the Tenable Nessus plugin 304204 to detect vulnerable installations (Tenable Nessus, VulnCheck Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."