CVE-2025-55188
LOW7-Zip < 25.01 - Improper Link Resolution During Extraction
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2025-55188. PoCs published by hunters-sec, lunbun.
AI-analyzed exploit summary This PoC demonstrates CVE-2025-55188, a symlink arbitrary file write vulnerability in 7-Zip versions prior to 25.01. It crafts a malicious archive that, when extracted, overwrites arbitrary files via symbolic link traversal.
Description
7-Zip before 25.01 does not always properly handle symbolic links during extraction.
Exploits (2)
This PoC demonstrates CVE-2025-55188, a symlink arbitrary file write vulnerability in 7-Zip versions prior to 25.01. It crafts a malicious archive that, when extracted, overwrites arbitrary files via symbolic link traversal.
This repository contains proof-of-concept exploits for CVE-2025-55188, demonstrating arbitrary file write and code execution in 7-Zip via symlink and hardlink path traversal techniques. The exploits target both Linux and Windows systems by crafting malicious archive files.
References (14)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N