Absolute path traversal in zip:unzip/1,2
Vulnerability Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (stdlib modules) allows Absolute Path Traversal, File Manipulation. This vulnerability is associated with program files lib/stdlib/src/zip.erl and program routines zip:unzip/1, zip:unzip/2, zip:extract/1, zip:extract/2 unless the memory option is passed. This issue affects OTP from OTP 17.0 until OTP 28.0.1, OTP 27.3.4.1 and OTP 26.2.5.13, corresponding to stdlib from 2.0 until 7.0.1, 6.2.2.1 and 5.2.3.4.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-4748
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Wander Nauta
- Lukas Backström
- Björn Gustavsson
References
- https://github.com/erlang/otp/security/advisories/GHSA-9g37-pgj9-wrhc
- https://cna.erlef.org/cves/CVE-2025-4748.html
- https://osv.dev/vulnerability/EEF-CVE-2025-4748
- https://www.erlang.org/doc/system/versions.html#order-of-versions
- https://github.com/erlang/otp/pull/9941
- https://github.com/erlang/otp/commit/5a55feec10c9b69189d56723d8f237afa58d5d4f
- https://github.com/erlang/otp/commit/ba2f2bc5f45fcfd2d6201ba07990a678bbf4cc8f
- https://github.com/erlang/otp/commit/578d4001575aa7647ea1efd4b2b7e3afadcc99a5
More from Erlang
View All →Affected Vendor
Erlang
View all reports →