logo

Exploiting Erlang OTP with Zip files: CVE-2025-4748

ID: 211781ca-a47d-58de-bffc-c72d5d470e2c

STIX ID: report--211781ca-a47d-58de-bffc-c72d5d470e2c

Feed Name: GreyNoise Labs

Threat Score
60/100

Date Published: 2025-06-17

Date Updated: 2026-04-27

Author: remy

...
...

This report details CVE-2025-4748, an absolute path traversal vulnerability in the Erlang OTP zip module, and provides step-by-step reproduction and a proof-of-concept that creates a ZIP with an absolute path to overwrite /home/remy/.bashrc, demonstrating potential code execution on user login. The exploit is local by default but can lead to remote impact if archives are unpacked from untrusted network sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.