JRebel is a development productivity tool focused on enabling live code reloading during Java application development, with its exposure centered in the ZT-ZIP compression library. The observed vulnerability pattern involves path-traversal issues in archive-handling functionality, reflecting the risks inherent to pathname validation in compression and extraction workflows. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jrebel over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1002201MEDIUM zt-zip before 1.13 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during e | Jul 25, 2018 | 5.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jrebel.
Media articles that mention a CVE ID that affects a product developed by Jrebel — matched by CVE ID, not by vendor name.