7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. Interaction with this product is required to exploit this vulnerability but attack vectors may vary depending on the implementation.
The specific flaw exists within the handling of symbolic links in ZIP files. Crafted data in a ZIP file can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of a service account. Was ZDI-CAN-26753.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- CVSS 3.0 Base Score: 7
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| 7 Zip 7 Zip | — | Upgrade 7-Zip to the latest version | Nov 19, 2025 | Nov 19, 2025 |
| Amazon_linux_2023 | — | Upgrade 7zip-reduced-debuginfoUpgrade 7zip-standaloneUpgrade 7zip-standalone-debuginfoUpgrade p7zipUpgrade 7zip-reducedUpgrade 7zip-standalone-allUpgrade 7zip-debugsourceUpgrade 7zip-standalone-all-debuginfoUpgrade p7zip-docUpgrade 7zipUpgrade p7zip-pluginsUpgrade 7zip-debuginfo | Nov 27, 2025 | Nov 19, 2025 |
| Debian | — | Upgrade p7zipUpgrade 7zip | May 12, 2026 | May 12, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub