CVE-2025-67030: Path Traversal
Published Mar 25, 2026
·Updated
Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code
Affected Software
7 affected componentsFixes available
maven/org.codehaus.plexus/plexus-utils<6d780b3378829318ba5c2d29547e0012d5b29642
Microsoft cbl2 plexus-utils 3.3.0-3
Microsoft azl3 plexus-utils 3.3.0-4
Microsoft cbl2 plexus-utils 3.3.0-4
Microsoft azl3 plexus-utils 3.3.0-5
Codehaus-plexus Plexus-utils<3.6.1
Codehaus-plexus Plexus-utils>=4.0.0<4.0.3
Remediation
Patch Available
Patch Available
Event History
Mar 25, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via Red Hat·06:02 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·06:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Mar 29, 2026
Data Sourced
via Microsoft·08:02 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:02 AM
Severity
Updated
via Microsoft·08:02 AM
Affected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-67030?
CVE-2025-67030 has a critical severity level as it allows an attacker to execute arbitrary code.
2
How do I fix CVE-2025-67030?
To fix CVE-2025-67030, update plexus-utils to version 6d780b3378829318ba5c2d29547e0012d5b29642 or later.
3
What products are affected by CVE-2025-67030?
CVE-2025-67030 affects versions of plexus-utils prior to 6d780b3378829318ba5c2d29547e0012d5b29642.
4
What type of vulnerability is CVE-2025-67030?
CVE-2025-67030 is a Directory Traversal vulnerability in the extractFile method.
5
Can CVE-2025-67030 be exploited remotely?
Yes, CVE-2025-67030 can be exploited remotely, allowing attackers to execute arbitrary code on the affected system.