CVE-2025-67030: Codehaus-Plexus Plexus-Utils
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code
Affected products
- Codehaus-Plexus Plexus-Utils: before 3.6.1 (fixed in 3.6.1); from 4.0.0, before 4.0.3 (fixed in 4.0.3)
Published 2026-03-25. Last modified 2026-09-16.