CVE-2025-58438 is a critical directory traversal vulnerability affecting the internetarchive Python library versions 5.5.0 and below. The flaw in the File.download() method allows attackers to craft malicious filenames containing path traversal sequences, leading to files being written outside the intended directory. This can result in denial of service, privilege escalation, or remote code execution, particularly impacting Windows systems. With a CVSS score of 9.4 (CRITICAL), this vulnerability is easily exploitable over the network with low attack complexity and user interaction. While no active exploitation, public exploit code, or significant community discussion has been observed, immediate patching to version 5.5.1 is strongly recommended to mitigate the high risk posed by this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Jjjake | Internetarchive | < 5.5.1CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.