← Vulnerability feed

Vulnerability record · CVE-2025-67030 · published 25 March 2026

CVE-2025-67030: Codehaus-plexus plexus-utils path traversal vulnerability

CCodehaus Plexus · Plexus Utils

Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code

8.8 CVSS 3.1 High EPSS 0.66% · top 50.3% CWE-22 · Path traversal
8.8CVSS 3.1 base score
0.66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
37References
16 Sep 2026Last modified by NVD

Description

Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://gist.github.com/weaver4VD/3216dac645220f8c9b488362f61241ec Third Party Advisory
https://github.com/codehaus-plexus/plexus-utils/commit/6d780b3378829318ba5c2d29547e0012d5b29642 Patch
https://github.com/codehaus-plexus/plexus-utils/issues/294 Issue Tracking
https://github.com/codehaus-plexus/plexus-utils/pull/295 Issue TrackingPatch
https://github.com/codehaus-plexus/plexus-utils/pull/296 Issue TrackingPatch
https://access.redhat.com/errata/RHSA-2026:17668
https://access.redhat.com/errata/RHSA-2026:18054
https://access.redhat.com/errata/RHSA-2026:18055
https://access.redhat.com/errata/RHSA-2026:18059
https://access.redhat.com/errata/RHSA-2026:35990
https://access.redhat.com/errata/RHSA-2026:35991
https://access.redhat.com/errata/RHSA-2026:35992
https://access.redhat.com/errata/RHSA-2026:35996
https://access.redhat.com/errata/RHSA-2026:35997
https://access.redhat.com/errata/RHSA-2026:36012
https://access.redhat.com/errata/RHSA-2026:38500
https://access.redhat.com/errata/RHSA-2026:38514
https://access.redhat.com/errata/RHSA-2026:38796
https://access.redhat.com/errata/RHSA-2026:40841
https://access.redhat.com/errata/RHSA-2026:41948
https://access.redhat.com/errata/RHSA-2026:60239
https://access.redhat.com/errata/RHSA-2026:60246
https://access.redhat.com/errata/RHSA-2026:60247
https://access.redhat.com/errata/RHSA-2026:60248
https://access.redhat.com/errata/RHSA-2026:60249
https://access.redhat.com/errata/RHSA-2026:60250
https://access.redhat.com/errata/RHSA-2026:60251
https://access.redhat.com/errata/RHSA-2026:60252
https://access.redhat.com/errata/RHSA-2026:60254
https://access.redhat.com/errata/RHSA-2026:60256
https://access.redhat.com/errata/RHSA-2026:60259
https://access.redhat.com/errata/RHSA-2026:65126
https://access.redhat.com/errata/RHSA-2026:7109
https://access.redhat.com/errata/RHSA-2026:7380
https://access.redhat.com/security/cve/CVE-2025-67030
https://bugzilla.redhat.com/show_bug.cgi?id=2451409
https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-67030.json

Track CVE-2025-67030 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-1000487Codehaus-plexus plexus-utils os command injection vulnerabilityPlexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings.EPSS 6.5%7.5CVE-2022-4244Codehaus-plexus plexus-utils path traversal vulnerabilityA flaw was found in codeplex-codehaus. A directory traversal attack (also known as path traversal) aims to access files and directories stored outsid…EPSS 1.3%4.3CVE-2022-4245Codehaus-plexus plexus-utils xml injection vulnerabilityA flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comments for a --> sequence. This …EPSS 0.69%9.8CVE-2026-93616Checkpoint multi-domain security management path traversal vulnerabilityA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Managem…KEVEPSS 20%10.0CVE-2026-85706GitLab CE/EE repository commits API path traversal allows unauthenticated file readGitLab CE/EE contains improper path confinement and missing authentication enforcement in the repository commits API, allowing an unauthenticated use…KEVEPSS 91%analysed5.3CVE-2026-66384JFrog Artifactory path traversal in Docker cache pathAn authenticated user can write data outside the intended Docker cache path under specific remote-repository conditions in JFrog Artifactory. The fla…KEVEPSS 0.66%analysed9.8CVE-2026-59310VMware vCenter Syslog server path traversal leads to RCEVMware vCenter's Syslog server is affected by a directory traversal flaw (CWE-22) that allows a remote, unauthenticated attacker to execute arbitrary…KEVEPSS 2.6%analysed10.0CVE-2026-48282Adobe ColdFusion path traversal leads to remote code executionColdFusion versions 2025.9, 2023.20 and earlier contain a path traversal flaw (CWE-22) that allows an unauthenticated remote attacker to reach files …KEVEPSS 42%analysed

Source: NIST National Vulnerability Database (record CVE-2025-67030), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.