PT-2025-36397 · Unknown+3 · Internetarchive+3

Pengowray

·

Published

2025-09-05

·

Updated

2026-02-02

·

CVE-2025-58438

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions internetarchive versions 5.5.0 and below
Description The internetarchive library contains a directory traversal vulnerability in the File.download() method. The method does not properly sanitize user-supplied filenames or validate the final download path. A maliciously crafted filename containing path traversal sequences (e.g., ../../../../windows/system32/file.txt) or illegal characters could allow an attacker to write files outside the intended target directory. This could lead to a denial of service, privilege escalation, or remote code execution. All operating systems are affected, with a potentially higher risk for Windows systems.
Recommendations Update to internetarchive version 5.5.1 or later.

Exploit

Fix

DoS

LPE

RCE

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-58438
DLA-4314-1
DSA-6035-1
GHSA-WX3R-V6H7-FRJP
USN-7989-1

Affected Products

Debian
Linuxmint
Ubuntu
Internetarchive