CVE-2025-4748

EUVD-2025-18414
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (stdlib modules) allows Absolute Path Traversal, File Manipulation. This vulnerability is associated with program files lib/stdlib/src/zip.erl and program routines zip:unzip/1, zip:unzip/2, zip:extract/1, zip:extract/2 unless the memory option is passed.

This issue affects OTP from OTP 17.0 until OTP 28.0.1, OTP 27.3.4.1 and OTP 26.2.5.13, corresponding to stdlib from 2.0 until 7.0.1, 6.2.2.1 and 5.2.3.4.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 59%
Debian logo
Debian Releases
Debian Product
Codename
erlang
bookworm
1:25.2.3+dfsg-1+deb12u4
fixed
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
1:23.2.6+dfsg-1+deb11u4
fixed
forky
1:27.3.4.11+dfsg-1
fixed
sid
1:27.3.4.11+dfsg-7
fixed
trixie
1:27.3.4.1+dfsg-1+deb13u2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
erlang
bionic
needs-triage
focal
needs-triage
jammy
Fixed 1:24.2.1+dfsg-1ubuntu0.5
released
noble
Fixed 1:25.3.2.8+dfsg-1ubuntu4.4
released
oracular
ignored
plucky
Fixed 1:27.3+dfsg-1ubuntu1.2
released
questing
Fixed 1:27.3.4.1+dfsg-1
released
resolute
Fixed 1:27.3.4.1+dfsg-1
released
trusty
needs-triage
xenial
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
erlang
suse enterprise sap 15 SP6
23.3.4.19-150300.3.23.3
fixed
suse enterprise sap 15 SP7
23.3.4.19-150300.3.23.3
fixed
suse enterprise server 15 SP4
23.3.4.19-150300.3.23.3
fixed
suse enterprise server 15 SP6
23.3.4.19-150300.3.23.3
fixed
suse enterprise server 15 SP7
23.3.4.19-150300.3.23.3
fixed
erlang-epmd
suse enterprise sap 15 SP6
23.3.4.19-150300.3.23.3
fixed
suse enterprise sap 15 SP7
23.3.4.19-150300.3.23.3
fixed
suse enterprise server 15 SP4
23.3.4.19-150300.3.23.3
fixed
suse enterprise server 15 SP6
23.3.4.19-150300.3.23.3
fixed
suse enterprise server 15 SP7
23.3.4.19-150300.3.23.3
fixed
erlang26
suse enterprise sap 15 SP6
26.2.1-150300.7.14.3
fixed
suse enterprise sap 15 SP7
26.2.1-150300.7.14.3
fixed
suse enterprise server 15 SP6
26.2.1-150300.7.14.3
fixed
suse enterprise server 15 SP7
26.2.1-150300.7.14.3
fixed
erlang26-epmd
suse enterprise sap 15 SP6
26.2.1-150300.7.14.3
fixed
suse enterprise sap 15 SP7
26.2.1-150300.7.14.3
fixed
suse enterprise server 15 SP6
26.2.1-150300.7.14.3
fixed
suse enterprise server 15 SP7
26.2.1-150300.7.14.3
fixed