cbcvebase.
CVE-2025-67030
published 2026-03-25

CVE-2025-67030: Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642…

PriorityP350high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.66%
47.6th percentile
Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code

Affected

6 ranges
VendorProductVersion rangeFixed in
codehaus-plexusplexus-utils< 3.6.13.6.1
codehaus-plexusplexus-utils>= 4.0.0 < 4.0.34.0.3
debianplexus-utils2
msrcazl3_plexus-utils_3.3.0-4_on_azure_linux_3.0
msrccbl2_javapackages-bootstrap_1.5.0-7_on_cbl_mariner_2.0
msrccbl2_plexus-utils_3.3.0-3_on_cbl_mariner_2.0

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.