CVE-2025-4748 - CVE House
Back to Database
Status published Medium CVE-2025-4748

Absolute path traversal in zip:unzip/1,2

Vulnerability Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (stdlib modules) allows Absolute Path Traversal, File Manipulation. This vulnerability is associated with program files lib/stdlib/src/zip.erl and program routines zip:unzip/1, zip:unzip/2, zip:extract/1, zip:extract/2 unless the memory option is passed. This issue affects OTP from OTP 17.0 until OTP 28.0.1, OTP 27.3.4.1 and OTP 26.2.5.13, corresponding to stdlib from 2.0 until 7.0.1, 6.2.2.1 and 5.2.3.4.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-4748

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Wander Nauta
  • Lukas Backström
  • Björn Gustavsson

Affected Vendor

Affected Software

OTP
Vulnerable Versions:
2.0, 17.0, 07b8f441ca711f9812fad9e9115bab3c3aa92f79

Timeline

Official Publish: June 16th, 2025
Last Modified: May 27th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)