CVE-2025-67030 is a Directory Traversal vulnerability (CWE-22) in the extractFile method of org.codehaus.plexus.util.Expand within plexus-utils versions prior to 6d780b3378829318ba5c2d29547e0012d5b29642. This flaw is rated 8.8 HIGH (CVSS:3.1) and allows an unauthenticated attacker to achieve arbitrary code execution over the network with low attack complexity, though user interaction is required. There is currently no evidence of active exploitation, no public exploit code available, and minimal community discussion or media coverage regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.6.1CPE matchmatch criteria | cpe:2.3:a:codehaus-plexus:plexus-utils:*:*:*:*:*:*:*:* | ||
>= 4.0.0, < 4.0.3CPE matchmatch criteria | cpe:2.3:a:codehaus-plexus:plexus-utils:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Plexus-Utils has a Directory Traversal vulnerability in its extractFile method
Mar 25, 2026Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code
Mar 10, 2026