Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6fmv-xxpf-w3cw | Plexus-Utils has a Directory Traversal vulnerability in its extractFile method |
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:codehaus-plexus:plexus-utils:*:*:*:*:*:*:*:* |
Fri, 27 Mar 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 26 Mar 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 |
Thu, 26 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Codehaus-plexus
Codehaus-plexus plexus-utils |
|
| Vendors & Products |
Codehaus-plexus
Codehaus-plexus plexus-utils |
Thu, 26 Mar 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Directory Traversal in Plexus Utils ExtractFile Leading to Arbitrary Code Execution | org.codehaus.plexus:plexus-utils: Plexus-utils: Directory Traversal in extractFile method |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Wed, 25 Mar 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Directory Traversal in Plexus Utils ExtractFile Leading to Arbitrary Code Execution | |
| Weaknesses | CWE-22 CWE-94 |
Wed, 25 Mar 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code | |
| References |
|
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-03-27T19:34:53.752Z
Reserved: 2025-12-08T00:00:00.000Z
Link: CVE-2025-67030
No data.
Status : Analyzed
Published: 2026-03-25T18:16:25.880
Modified: 2026-05-01T17:12:22.820
Link: CVE-2025-67030
OpenCVE Enrichment
Updated: 2026-04-02T07:59:19Z
Github GHSA