7-Zip before 25.01 does not always properly handle symbolic links during extraction.
References
Link | Resource |
---|---|
https://github.com/ip7z/7zip/compare/25.00...25.01 | Product |
https://github.com/ip7z/7zip/releases/tag/25.01 | Release Notes |
https://github.com/lunbun/CVE-2025-55188/ | Exploit |
https://lunbun.dev/blog/cve-2025-55188/ | Exploit Third Party Advisory |
https://sourceforge.net/p/sevenzip/discussion/45797/thread/da14cd780b/ | Product |
https://www.openwall.com/lists/oss-security/2025/08/09/1 | Mailing List Third Party Advisory |
https://youtu.be/sWT6M1cfnwM | Exploit |
Configurations
History
29 Sep 2025, 22:59
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/lunbun/CVE-2025-55188/ - Exploit | |
References | () https://lunbun.dev/blog/cve-2025-55188/ - Exploit, Third Party Advisory | |
References | () https://www.openwall.com/lists/oss-security/2025/08/09/1 - Mailing List, Third Party Advisory | |
References | () https://youtu.be/sWT6M1cfnwM - Exploit |
08 Sep 2025, 07:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
18 Aug 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
18 Aug 2025, 04:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
14 Aug 2025, 17:28
Type | Values Removed | Values Added |
---|---|---|
First Time |
7-zip 7-zip
7-zip |
|
CPE | cpe:2.3:a:7-zip:7-zip:*:*:*:*:*:*:*:* | |
References | () https://github.com/ip7z/7zip/compare/25.00...25.01 - Product | |
References | () https://github.com/ip7z/7zip/releases/tag/25.01 - Release Notes | |
References | () https://sourceforge.net/p/sevenzip/discussion/45797/thread/da14cd780b/ - Product |
11 Aug 2025, 18:32
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
10 Aug 2025, 01:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 3.6 |
08 Aug 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-08 21:15
Updated : 2025-09-29 22:59
NVD link : CVE-2025-55188
Mitre link : CVE-2025-55188
CVE.ORG link : CVE-2025-55188
JSON object : View
Products Affected
7-zip
- 7-zip
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')