⚡️🚨 NEW - 7-Zip Vulnerabilities Let Attackers…

⚡️🚨 NEW - 7-Zip Vulnerabilities Let Attackers…

⚡️🚨 NEW - 7-Zip Vulnerabilities Let Attackers Execute Arbitrary Code Remotely

Two high-severity vulnerabilities have been discovered in the popular open-source file archiver, 7-Zip, which could allow remote attackers to execute arbitrary code.

Identified as CVE-2025-11001 and CVE-2025-11002, the flaws affect all versions of the software prior to the latest release and require immediate patching.

The core of both vulnerabilities lies within the way 7-Zip handles symbolic links embedded in ZIP archives.

When a user with a vulnerable version of 7-Zip attempts to decompress the archive, the flawed process can be manipulated to perform a directory traversal.

This post and comments are published on Nostr.