PT-2025-36397 · Unknown+3 · Internetarchive+3
Pengowray
·
Published
2025-09-05
·
Updated
2026-02-02
·
CVE-2025-58438
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
internetarchive versions 5.5.0 and below
Description
The internetarchive library contains a directory traversal vulnerability in the
File.download() method. The method does not properly sanitize user-supplied filenames or validate the final download path. A maliciously crafted filename containing path traversal sequences (e.g., ../../../../windows/system32/file.txt) or illegal characters could allow an attacker to write files outside the intended target directory. This could lead to a denial of service, privilege escalation, or remote code execution. All operating systems are affected, with a potentially higher risk for Windows systems.Recommendations
Update to internetarchive version 5.5.1 or later.
Exploit
Fix
DoS
LPE
RCE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Linuxmint
Ubuntu
Internetarchive