CVE-2018-25046: Cloudfoundry Archiver

Critical severity, CVSS 9.1. EPSS: 1.2% chance of exploitation in the next 30 days.

Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.

Affected products

  • Cloudfoundry Archiver: before 2018-05-23 (fixed in 2018-05-23)

Published 2022-12-27. Last modified 2026-06-17.