CVE-2025-67030: Codehaus-Plexus Plexus-Utils

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code

Affected products

  • Codehaus-Plexus Plexus-Utils: before 3.6.1 (fixed in 3.6.1); from 4.0.0, before 4.0.3 (fixed in 4.0.3)

Published 2026-03-25. Last modified 2026-09-16.