Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.7%top 51%

CVE-2025-67030: n/a

0
High
Published: 03/25/2026 (03/25/2026, 00:00:00 UTC)
Source: GCVE Database

Description

Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code

CVSS v3.1

Score 8.8high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected software

redhat/plexus-utils
pkg:rpm/redhat/plexus-utils
Affected versions
=10<10.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 18:16:28 UTC

Technical Analysis

The vulnerability CVE-2025-67030 exists in the extractFile method of the org.codehaus.plexus.util.Expand class within plexus-utils. It is a directory traversal vulnerability (CWE-22) that can be exploited to execute arbitrary code. The affected versions include =10, <10.2, >=8.0.0 <8.10.1, and >=9.2.0 <9.2.2. Red Hat has released security advisories RHSA-2026:35990 and RHSA-2026:35991 detailing the issue and providing updated plexus-utils packages to remediate the vulnerability. The CVSS v3.1 score is 8.8 (High), indicating a network attack vector with low complexity, no privileges required, user interaction required, and high impact on confidentiality, integrity, and availability. The vendor advisories confirm the availability of official patches and provide instructions for applying updates.

Potential Impact

Successful exploitation of this directory traversal vulnerability allows an attacker to execute arbitrary code on affected systems. The CVSS score of 8.8 reflects a high severity impact with potential full compromise of confidentiality, integrity, and availability. There are no known exploits in the wild at this time. The vulnerability affects multiple Red Hat Enterprise Linux versions and related products using plexus-utils.

Mitigation Recommendations

Red Hat has released official security updates for plexus-utils that fix this vulnerability. Users should apply the updated packages as detailed in Red Hat advisories RHSA-2026:35990 and RHSA-2026:35991. The advisories provide package names and versions for affected Red Hat Enterprise Linux 9.2 and 10.0 distributions. Applying these updates will remediate the vulnerability. No additional mitigation steps are required beyond applying the official patches.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:38514
Cve Count
1
Additional Cves
[]
Cvss Version
3.1

Threat ID: 6a54adf568715ace438f7157

Added to database: 07/13/2026, 09:20:53 UTC

Last enriched: 08/12/2026, 18:16:28 UTC

Last updated: 09/05/2026, 10:52:06 UTC

Views: 51

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses