pf4j before 20c2f80 has a path traversal vulnerability in the extract() function of Unzip.java, where improper handling of zip entry names can allow directory traversal or Zip Slip attacks, due to a lack of proper path normalization and validation.
References
| Link | Resource |
|---|---|
| https://gist.github.com/weaver4VD/410f23adb24ef5f5077f021f4393e705 | Third Party Advisory |
| https://github.com/pf4j/pf4j/commit/20c2f80089d1ea779e22c2de5f109a0bce4e1b14 | Patch |
| https://github.com/pf4j/pf4j/issues/618 | Issue Tracking Third Party Advisory |
| https://github.com/pf4j/pf4j/issues/623 | Exploit Issue Tracking Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-03-25 19:16
Updated : 2026-06-17 10:03
NVD link : CVE-2025-70952
Mitre link : CVE-2025-70952
CVE.ORG link : CVE-2025-70952
JSON object : View
Products Affected
pf4j_project
- pf4j
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
