Am I affected?
This record states its affected versions in a form that can't be compared automatically.
≥
2.0
and up
affected
→
7.0.1
not affected
→
6.2.2.1
not affected
→
5.2.3.4
not affected
every other version:
unknown
Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (stdlib modules) allows Absolute Path Traversal, File Manipulation.
This vulnerability is associated with program files lib/stdlib/src/zip.erl and program routines zip:unzip/1, zip:unzip/2, zip:extract/1, zip:extract/2 unless the memory option is passed.
This issue affects OTP from OTP 17.0 before OTP 28.0.1, OTP 27.3.4.1 and OTP 26.2.5.13, corresponding to stdlib from 2.0 before 7.0.1, 6.2.2.1 and 5.2.3.4.
Weaknesses & attack patterns
Weakness
CWE-22
·
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
in catalog →
MITRE ↗
Affected — Erlang / stdlib Repository ↗
≥
2.0
and up
affected
→
7.0.1
not affected
→
6.2.2.1
not affected
→
5.2.3.4
not affected
every other version:
unknown
default status
unknown
cpe
cpe:2.3:a:erlang:erlang/otp:*:*:*:*:*:*:*:*
modules · source files · routines
modules
stdlib
source files
lib/stdlib/src/zip.erl
routines
zip:unzip/1 · zip:unzip/2 · zip:extract/1 · zip:extract/2
Affected — GitHub / erlang/otp Repository ↗
≥
17.0
and up
affected
→
28.0.1
not affected
→
27.3.4.1
not affected
→
26.2.5.13
not affected
≥
07b8f44
and up
affected
→
d9454db
not affected
→
9b7b543
not affected
→
0ac548b
not affected
every other version:
unknown
default status
unknown
cpe
cpe:2.3:a:erlang:erlang/otp:*:*:*:*:*:*:*:*
modules · source files · routines
modules
stdlib
source files
lib/stdlib/src/zip.erl
routines
zip:unzip/1 · zip:unzip/2 · zip:extract/1 · zip:extract/2
Workarounds
You can use
zip:list_dir/1 on the archive and verify that no files contain absolute paths before extracting the archive to disk.References
github.com/erlang/otp ·
GHSA-9g37-pgj9-wrhc ↗
vendor-advisory
osv.dev ·
EEF-CVE-2025-4748 ↗
related
Credits
Wander Nauta
Finder
Lukas Backström
Remediation developer
Björn Gustavsson
Remediation reviewer
CVSS breakdown
MEDIUM 4.8
open in calculator →
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L