PT-2025-16188 · Unknown · Mholt/Archiver

Published

2025-04-13

·

Updated

2025-08-08

·

CVE-2025-3445

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions: mholt/archiver versions (affected versions not specified)
Description: A Path Traversal "Zip Slip" vulnerability has been identified in the mholt/archiver library in Go. This issue allows an attacker to use a crafted ZIP file containing path traversal symlinks to create or overwrite files with the user's privileges or the application utilizing the library. When using the archiver.Unarchive functionality with ZIP files, a crafted ZIP file can be extracted in such a way that it writes files to the affected system with the same privileges as the application executing this vulnerable functionality. This could lead to sensitive files being overwritten, potentially resulting in privilege escalation, code execution, and other severe outcomes.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-3445
GHSA-7VPP-9CXJ-Q8GV
GO-2025-3605
OPENSUSE-SU-2025:15001-1
OPENSUSE-SU-2025:15424-1

Affected Products

Mholt/Archiver