CVE-2025-69601
MEDIUM66biolinks v44.0.0 - Path Traversal and Arbitrary File Write via ZIP Archive Extraction
Title source: llmDescription
A directory traversal (Zip Slip) vulnerability exists in the “Static Sites” feature of 66biolinks v44.0.0 by AltumCode. Uploaded ZIP archives are automatically extracted without validating or sanitizing file paths. An attacker can include traversal sequences (e.g., ../) in ZIP entries to write files outside the intended extraction directory. This allows static files (html, js, css, images) file write to unintended locations, or overwriting existing HTML files, potentially leading to content defacement and, in certain deployments, further impact if sensitive files are overwritten.
References (1)
Core 1
Core References
Exploit, Third Party Advisory
https://gist.github.com/Waqar-Arain/9cd59aa74de540eeb3b09d15bac35e36
Scores
CVSS v3
6.5
EPSS
0.0063
EPSS Percentile
45.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (1)
altumcode/66biolinks
44.0.0
Published
Jan 28, 2026
Tracked Since
Feb 18, 2026