CVE-2025-4748

EUVD-2025-18414
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (stdlib modules) allows Absolute Path Traversal, File Manipulation. This vulnerability is associated with program files lib/stdlib/src/zip.erl and program routines zip:unzip/1, zip:unzip/2, zip:extract/1, zip:extract/2 unless the memory option is passed.

This issue affects OTP from OTP 17.0 until OTP 28.0.1, OTP 27.3.4.1 and OTP 26.2.5.13, corresponding to stdlib from 2.0 until 7.0.1, 6.2.2.1 and 5.2.3.4.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 18%
Debian logo
Debian Releases
Debian Product
Codename
erlang
bookworm
1:25.2.3+dfsg-1+deb12u3
fixed
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
1:23.2.6+dfsg-1+deb11u3
fixed
forky
1:27.3.4.6+dfsg-1
fixed
sid
1:27.3.4.6+dfsg-1
fixed
trixie
1:27.3.4.1+dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
erlang
bionic
needs-triage
focal
needs-triage
jammy
Fixed 1:24.2.1+dfsg-1ubuntu0.5
released
noble
Fixed 1:25.3.2.8+dfsg-1ubuntu4.4
released
oracular
ignored
plucky
Fixed 1:27.3+dfsg-1ubuntu1.2
released
questing
Fixed 1:27.3.4.1+dfsg-1
released
trusty
needs-triage
xenial
needs-triage