CVE-2025-54386 - CVE House
Back to Database
Status published High CVE-2025-54386

Traefik's Client Plugin is Vulnerable to Path Traversal, Arbitrary File Overwrites and Remote Code Execution

Vulnerability Description

Traefik is an HTTP reverse proxy and load balancer. In versions 2.11.27 and below, 3.0.0 through 3.4.4 and 3.5.0-rc1, a path traversal vulnerability was discovered in WASM Traefik’s plugin installation mechanism. By supplying a maliciously crafted ZIP archive containing file paths with ../ sequences, an attacker can overwrite arbitrary files on the system outside of the intended plugin directory. This can lead to remote code execution (RCE), privilege escalation, persistence, or denial of service. This is fixed in versions 2.11.28, 3.4.5 and 3.5.0.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-54386

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

traefik
Vulnerable Versions:
<= 2.11.27, < 2.11.28, <= 3.0.0, < 3.4.5, >= 3.5.0-rc1, < 3.5.0-rc2

Timeline

Official Publish: August 1st, 2025
Last Modified: August 4th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)