CVE-2025-67030: n/a
Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code
AI Analysis
Technical Summary
The vulnerability CVE-2025-67030 exists in the extractFile method of the org.codehaus.plexus.util.Expand class within plexus-utils. It is a directory traversal vulnerability (CWE-22) that can be exploited to execute arbitrary code. The affected versions include =10, <10.2, >=8.0.0 <8.10.1, and >=9.2.0 <9.2.2. Red Hat has released security advisories RHSA-2026:35990 and RHSA-2026:35991 detailing the issue and providing updated plexus-utils packages to remediate the vulnerability. The CVSS v3.1 score is 8.8 (High), indicating a network attack vector with low complexity, no privileges required, user interaction required, and high impact on confidentiality, integrity, and availability. The vendor advisories confirm the availability of official patches and provide instructions for applying updates.
Potential Impact
Successful exploitation of this directory traversal vulnerability allows an attacker to execute arbitrary code on affected systems. The CVSS score of 8.8 reflects a high severity impact with potential full compromise of confidentiality, integrity, and availability. There are no known exploits in the wild at this time. The vulnerability affects multiple Red Hat Enterprise Linux versions and related products using plexus-utils.
Mitigation Recommendations
Red Hat has released official security updates for plexus-utils that fix this vulnerability. Users should apply the updated packages as detailed in Red Hat advisories RHSA-2026:35990 and RHSA-2026:35991. The advisories provide package names and versions for affected Red Hat Enterprise Linux 9.2 and 10.0 distributions. Applying these updates will remediate the vulnerability. No additional mitigation steps are required beyond applying the official patches.
CVE-2025-67030: n/a
Description
Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code
CVSS v3.1
Score 8.8high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2025-67030 exists in the extractFile method of the org.codehaus.plexus.util.Expand class within plexus-utils. It is a directory traversal vulnerability (CWE-22) that can be exploited to execute arbitrary code. The affected versions include =10, <10.2, >=8.0.0 <8.10.1, and >=9.2.0 <9.2.2. Red Hat has released security advisories RHSA-2026:35990 and RHSA-2026:35991 detailing the issue and providing updated plexus-utils packages to remediate the vulnerability. The CVSS v3.1 score is 8.8 (High), indicating a network attack vector with low complexity, no privileges required, user interaction required, and high impact on confidentiality, integrity, and availability. The vendor advisories confirm the availability of official patches and provide instructions for applying updates.
Potential Impact
Successful exploitation of this directory traversal vulnerability allows an attacker to execute arbitrary code on affected systems. The CVSS score of 8.8 reflects a high severity impact with potential full compromise of confidentiality, integrity, and availability. There are no known exploits in the wild at this time. The vulnerability affects multiple Red Hat Enterprise Linux versions and related products using plexus-utils.
Mitigation Recommendations
Red Hat has released official security updates for plexus-utils that fix this vulnerability. Users should apply the updated packages as detailed in Red Hat advisories RHSA-2026:35990 and RHSA-2026:35991. The advisories provide package names and versions for affected Red Hat Enterprise Linux 9.2 and 10.0 distributions. Applying these updates will remediate the vulnerability. No additional mitigation steps are required beyond applying the official patches.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:38514
- Cve Count
- 1
- Additional Cves
- []
- Cvss Version
- 3.1
Threat ID: 6a54adf568715ace438f7157
Added to database: 07/13/2026, 09:20:53 UTC
Last enriched: 08/12/2026, 18:16:28 UTC
Last updated: 09/05/2026, 10:52:06 UTC
Views: 51
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.