CVE-2025-4748
Last modified
CVE-2025-4748 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (stdlib modules) allows Absolute Path Traversal, File Manipulation. This vulnerability is associated with program files lib/stdlib/src/zip.erl and program routines zip:unzip/1, zip:unzip/2, zip:extract/1, zip:extract/2 unless the memory option is passed. This issue affects OTP from OTP 17.0 before OTP 28.0.1, OTP 27.3.4.1 and OTP 26.2.5.13, corresponding to stdlib from 2.0 before 7.0.1, 6.2.2.1 and 5.2.3.4.. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (stdlib modules) allows Absolute Path Traversal, File Manipulation. This vulnerability is associated with program files lib/stdlib/src/zip.erl and program routines zip:unzip/1, zip:unzip/2, zip:extract/1, zip:extract/2 unless the memory option is passed. This issue affects OTP from OTP 17.0 before OTP 28.0.1, OTP 27.3.4.1 and OTP 26.2.5.13, corresponding to stdlib from 2.0 before 7.0.1, 6.2.2.1 and 5.2.3.4.
Metrics
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-4748?
How severe is CVE-2025-4748?
How do I fix CVE-2025-4748?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-47474Improper Control of Filename for Include/Require Statement i…8.1
- CVE-2025-47475Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2025-47476Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2025-47477Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2025-47478Improper Neutralization of Special Elements used in an SQL C…8.5
- CVE-2025-47479Weak Authentication vulnerability in AresIT WP Compress wp-c…9.8
- CVE-2025-47480Missing Authorization vulnerability in Iqonic Design Graphin…5.4
- CVE-2025-47481Improper Control of Generation of Code ('Code Injection') vu…5.3
- CVE-2025-47482Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2025-47483Server-Side Request Forgery (SSRF) vulnerability in Iulia Ca…4.9
- CVE-2025-47484Server-Side Request Forgery (SSRF) vulnerability in Oliver C…6.4
- CVE-2025-47485Missing Authorization vulnerability in CozyThemes Cozy Block…5.3
Are you affected by CVE-2025-4748?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
