PT-2026-28076 · Apache+1 · Plexus-Utils+1

CVE-2025-67030

·

Published

2026-03-25

·

Updated

2026-08-27

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions plexus-utils versions prior to 6d780b3378829318ba5c2d29547e0012d5b29642
Description A directory traversal issue exists in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils. This allows an attacker to execute arbitrary code.
Recommendations Update plexus-utils to a version newer than 6d780b3378829318ba5c2d29547e0012d5b29642.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:38500
ALSA-2026:38514
ALSA-2026:38796
ALSA-2026:40841
ALSA-2026:41948
AZL-81041
CLEANSTART-2026-AO61361
CLEANSTART-2026-PV53006
CVE-2025-67030
GHSA-6FMV-XXPF-W3CW
OPENSUSE-SU-2026:10439-1
OPENSUSE-SU-2026:20535-1
RHSA-2026:18054
RHSA-2026:18055
RHSA-2026:35990
RHSA-2026:35991
RHSA-2026:35992
RHSA-2026:35996
RHSA-2026:35997
RHSA-2026:36012
RHSA-2026:38500
RHSA-2026:38514
RHSA-2026:38796
RHSA-2026:40841
RHSA-2026:41948
SUSE-SU-2026:1396-1
SUSE-SU-2026:21194-1

Affected Products

Rocky Linux
Plexus-Utils