FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Erlang - Absolute Path in Zip Module

Affected packages
17.0 <= erlang < 26.2.5.13,4
erlang-runtime26 < 26.2.5.13
erlang-runtime27 < 27.3.4.1
erlang-runtime28 < 28.0.1

Details

VuXML ID 237f4f57-b50f-11f0-ae9b-b42e991fc52e
Discovery 2025-06-16
Entry 2025-10-29

https://github.com/erlang/otp/security/advisories/GHSA-9g37-pgj9-wrhc reports:

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (stdlib modules) allows Absolute Path Traversal, File Manipulation. This vulnerability is associated with program files lib/stdlib/src/zip.erl and program routines zip:unzip/1, zip:unzip/2, zip:extract/1, zip:extract/2unless the memory option is passed. This issue affects OTP from OTP 17.0 until OTP28.0.1, OTP27.3.4.1 and OTP26.2.5.13, corresponding to stdlib from 2.0 until 7.0.1, 6.2.2.1 and 5.2.3.4.

References

CVE Name CVE-2025-4748
URL https://cveawg.mitre.org/api/cve/CVE-2025-4748