Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-67030

33
FAUCET Score

CVE-2025-67030 is a Directory Traversal vulnerability (CWE-22) in the extractFile method of org.codehaus.plexus.util.Expand within plexus-utils versions prior to 6d780b3378829318ba5c2d29547e0012d5b29642. This flaw is rated 8.8 HIGH (CVSS:3.1) and allows an unauthenticated attacker to achieve arbitrary code execution over the network with low attack complexity, though user interaction is required. There is currently no evidence of active exploitation, no public exploit code available, and minimal community discussion or media coverage regarding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.6.1CPE matchmatch criteria
cpe:2.3:a:codehaus-plexus:plexus-utils:*:*:*:*:*:*:*:*
>= 4.0.0, < 4.0.3CPE matchmatch criteria
cpe:2.3:a:codehaus-plexus:plexus-utils:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.66%
Probability of exploitation in next 30 days
EPSS Percentile
47.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0066 is in the 49th percentile among its peer group of 14,875 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (11)

github_advisorypatch availablevia nvd_reference
View patch
mavenpatch availablevia ghsa
Product: org.codehaus.plexus:plexus-utilsFixed in: 3.6.1
mavenpatch availablevia ghsa
Product: org.codehaus.plexus:plexus-utilsFixed in: 4.0.3
microsoftpatch availablevia msrc
Product: 21085-17084Fixed in: 3.3.0-5
microsoftpatch availablevia msrc
Product: azl3 plexus-utils 3.3.0-5 on Azure Linux 3.0Fixed in: 3.3.0-5
microsoftpatch availablevia msrc
Product: azl3 plexus-utils 3.3.0-4 on Azure Linux 3.0Fixed in: 3.3.0-5
microsoftpatch availablevia msrc
Product: cbl2 plexus-utils 3.3.0-4 on CBL Mariner 2.0Fixed in: 3.3.0-4
microsoftpatch availablevia msrc
Product: cbl2 plexus-utils 3.3.0-3 on CBL Mariner 2.0Fixed in: 3.3.0-4
microsoftpatch availablevia msrc
Product: 21149-17086Fixed in: 3.3.0-4
microsoftpatch availablevia msrc
Product: 21086-17086Fixed in: 3.3.0-4
microsoftpatch availablevia msrc
Product: 21148-17084Fixed in: 3.3.0-5

Vendor Advisories (2)

mavenGHSA-6fmv-xxpf-w3cwhigh

Plexus-Utils has a Directory Traversal vulnerability in its extractFile method

Mar 25, 2026
microsoft2026-Mar/CVE-2025-67030Important

Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code

Mar 10, 2026

References

access.redhat.com / errata/RHSA-2026:17668
access.redhat.com / errata/RHSA-2026:18054
access.redhat.com / errata/RHSA-2026:18055
access.redhat.com / errata/RHSA-2026:18059
access.redhat.com / errata/RHSA-2026:35990
access.redhat.com / errata/RHSA-2026:35991
access.redhat.com / errata/RHSA-2026:35992
access.redhat.com / errata/RHSA-2026:35996
access.redhat.com / errata/RHSA-2026:35997
access.redhat.com / errata/RHSA-2026:36012
access.redhat.com / errata/RHSA-2026:38500
access.redhat.com / errata/RHSA-2026:38514
access.redhat.com / errata/RHSA-2026:38796
access.redhat.com / errata/RHSA-2026:40841
access.redhat.com / errata/RHSA-2026:41948
access.redhat.com / errata/RHSA-2026:7109
access.redhat.com / errata/RHSA-2026:7380
access.redhat.com / security/cve/CVE-2025-67030
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2025/cve-2025-67030.json
gist.github.com / weaver4VD/3216dac645220f8c9b488362f61241ec
Third Party Advisory
github.com / codehaus-plexus/plexus-utils/commit/6d780b3378829318ba5c2d29547e0012d5b29642
Patch
github.com / codehaus-plexus/plexus-utils/issues/294
Issue Tracking
github.com / codehaus-plexus/plexus-utils/pull/295
Issue TrackingPatch
github.com / codehaus-plexus/plexus-utils/pull/296
Issue TrackingPatch