{"id":"GHSA-6fmv-xxpf-w3cw","summary":"Plexus-Utils has a Directory Traversal vulnerability in its extractFile method ","details":"Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code","aliases":["CVE-2025-67030"],"modified":"2026-07-17T21:12:41.534133824Z","published":"2026-03-25T18:31:55Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-03-27T19:40:25Z","nvd_published_at":"2026-03-25T18:16:25Z","cwe_ids":["CWE-22"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-67030"},{"type":"WEB","url":"https://github.com/codehaus-plexus/plexus-utils/issues/294"},{"type":"WEB","url":"https://github.com/codehaus-plexus/plexus-utils/pull/295"},{"type":"WEB","url":"https://github.com/codehaus-plexus/plexus-utils/pull/296"},{"type":"WEB","url":"https://github.com/codehaus-plexus/plexus-utils/commit/6d780b3378829318ba5c2d29547e0012d5b29642"},{"type":"WEB","url":"https://gist.github.com/weaver4VD/3216dac645220f8c9b488362f61241ec"},{"type":"PACKAGE","url":"https://github.com/codehaus-plexus/plexus-utils"},{"type":"WEB","url":"https://github.com/codehaus-plexus/plexus-utils/releases/tag/plexus-utils-4.0.3"}],"affected":[{"package":{"name":"org.codehaus.plexus:plexus-utils","ecosystem":"Maven","purl":"pkg:maven/org.codehaus.plexus/plexus-utils"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0"},{"fixed":"4.0.3"}]}],"versions":["4.0.0","4.0.1","4.0.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-6fmv-xxpf-w3cw/GHSA-6fmv-xxpf-w3cw.json"}},{"package":{"name":"org.codehaus.plexus:plexus-utils","ecosystem":"Maven","purl":"pkg:maven/org.codehaus.plexus/plexus-utils"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6.1"}]}],"versions":["1.0.4","1.0.5","1.1","1.2","1.3","1.4","1.4-alpha-1","1.4.1","1.4.2","1.4.3","1.4.4","1.4.5","1.4.6","1.4.7","1.4.8","1.4.9","1.5","1.5.1","1.5.10","1.5.11","1.5.12","1.5.13","1.5.14","1.5.15","1.5.2","1.5.3","1.5.4","1.5.5","1.5.6","1.5.7","1.5.8","1.5.9","2.0.0","2.0.1","2.0.2","2.0.3","2.0.4","2.0.5","2.0.6","2.0.7","2.1","3.0","3.0.1","3.0.10","3.0.11","3.0.12","3.0.13","3.0.14","3.0.15","3.0.16","3.0.17","3.0.18","3.0.19","3.0.2","3.0.20","3.0.21","3.0.22","3.0.23","3.0.24","3.0.3","3.0.4","3.0.5","3.0.6","3.0.7","3.0.8","3.0.9","3.1.0","3.1.1","3.2.0","3.2.1","3.3.0","3.3.1","3.4.0","3.4.1","3.4.2","3.5.0","3.5.1","3.6.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-6fmv-xxpf-w3cw/GHSA-6fmv-xxpf-w3cw.json"}}],"schema_version":"1.9.0"}