PT-2025-29153 · Unknown · Callmanager
Lucas Tesson
+1
·
Published
2025-07-10
·
Updated
2025-08-14
·
CVE-2025-53632
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Chall-Manager versions prior to 0.1.4
Description:
Chall-Manager is a platform-agnostic system designed to initiate challenges on demand. A zip slip condition exists when decoding scenarios (zip archives) due to a lack of path validation during file writing. This issue does not require authentication or authorization for exploitation.
Recommendations:
Update to version 0.1.4 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Callmanager