PT-2025-36397 · Unknown+3 · Internetarchive+3

·

CVE-2025-58438

·

Published

2025-09-05

·

Updated

2026-06-29

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions internetarchive versions 5.5.0 and below
Description The internetarchive library contains a directory traversal vulnerability in the File.download() method. The method does not properly sanitize user-supplied filenames or validate the final download path. A maliciously crafted filename containing path traversal sequences (e.g., ../../../../windows/system32/file.txt) or illegal characters could allow an attacker to write files outside the intended target directory. This could lead to a denial of service, privilege escalation, or remote code execution. All operating systems are affected, with a potentially higher risk for Windows systems.
Recommendations Update to internetarchive version 5.5.1 or later.

Exploit

Fix

RCE

DoS

LPE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-58438
DLA-4314-1
DSA-6035-1
GHSA-WX3R-V6H7-FRJP
PYSEC-2026-357
USN-7989-1

Affected Products

Debian
Linuxmint
Ubuntu
Internetarchive