PT-2025-16188 · Unknown · Mholt/Archiver
Published
2025-04-13
·
Updated
2025-08-08
·
CVE-2025-3445
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions:
mholt/archiver versions (affected versions not specified)
Description:
A Path Traversal "Zip Slip" vulnerability has been identified in the mholt/archiver library in Go. This issue allows an attacker to use a crafted ZIP file containing path traversal symlinks to create or overwrite files with the user's privileges or the application utilizing the library. When using the
archiver.Unarchive functionality with ZIP files, a crafted ZIP file can be extracted in such a way that it writes files to the affected system with the same privileges as the application executing this vulnerable functionality. This could lead to sensitive files being overwritten, potentially resulting in privilege escalation, code execution, and other severe outcomes.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mholt/Archiver