CVE-2025-63371

HIGH

OneCommander 3.102.0.0 - Path Traversal

Title source: llm
STIX 2.1

Description

Milos Paripovic OneCommander 3.102.0.0 is vulnerable to Directory Traversal. The vulnerability resides in the ZIP file processing component, specifically in the functionality responsible for extracting and handling ZIP archive contents.

References (2)

Core 2

Scores

CVSS v3 7.5
EPSS 0.0062
EPSS Percentile 44.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
onecommander/onecommander 3.102.0.0
Published Nov 19, 2025
Tracked Since Feb 18, 2026