Exploiting Erlang OTP with Zip files: CVE-2025-4748
ID: 211781ca-a47d-58de-bffc-c72d5d470e2c
STIX ID: report--211781ca-a47d-58de-bffc-c72d5d470e2c
Feed Name: GreyNoise Labs
Threat Score
This report details CVE-2025-4748, an absolute path traversal vulnerability in the Erlang OTP zip module, and provides step-by-step reproduction and a proof-of-concept that creates a ZIP with an absolute path to overwrite /home/remy/.bashrc, demonstrating potential code execution on user login. The exploit is local by default but can lead to remote impact if archives are unpacked from untrusted network sources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
