CVE-2025-55188Link Following in 7-zip

CWE-59Link Following5 documents5 sources
Severity
3.6LOWNVD
EPSS
0.0%
top 88.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 8

Description

7-Zip before 25.01 does not always properly handle symbolic links during extraction.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages4 packages

NVD7-zip/7-zip< 25.01
debiandebian/7zip< 7zip 25.01+dfsg-1 (forky)
debiandebian/p7zip< 7zip 25.01+dfsg-1 (forky)
Debian7-zip/p7zip< 16.02+transitional.1

🔴Vulnerability Details

2
OSV
CVE-2025-55188: 7-Zip before 252025-08-08
GHSA
GHSA-58pw-r2v4-pwjv: 7-Zip before 252025-08-08

📋Vendor Advisories

1
Debian
CVE-2025-55188: 7zip - 7-Zip before 25.01 does not always properly handle symbolic links during extract...2025

🕵️Threat Intelligence

1
Wiz
CVE-2025-11002 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2025-55188 — Link Following in 7-zip | cvebase