Skip to content

[GHSA-58pw-r2v4-pwjv] Improve advisory details: reference incomplete fix for CVE-2025-11001#6791

Open
decsecre583 wants to merge 1 commit intogithub:decsecre583/advisory-improvement-6791from
decsecre583:decsecre583-patch-58
Open

[GHSA-58pw-r2v4-pwjv] Improve advisory details: reference incomplete fix for CVE-2025-11001#6791
decsecre583 wants to merge 1 commit intogithub:decsecre583/advisory-improvement-6791from
decsecre583:decsecre583-patch-58

Conversation

@decsecre583
Copy link

Proposed Change

Add cross-reference between CVE-2025-11001 and CVE-2025-55188 to document the incomplete fix relationship.

Evidence

  • CVE-2025-11001 fix (commit 3951499) adds IsSafePath validation to prevent symlink-based directory traversal during ZIP extraction
  • CVE-2025-55188 advisory states: "7-Zip before 25.01 does not always properly handle symbolic links during extraction" — same attack vector
  • CVE-2025-11001 fixed in 7-Zip 25.00; CVE-2025-55188 fixed in 25.01
  • Both are path traversal via symlinks during archive extraction
  • The version progression (25.00 → 25.01) with the same vulnerability class is strong evidence of an edge case bypass
  • Diff between versions: 25.00...25.01

@github-actions github-actions bot changed the base branch from main to decsecre583/advisory-improvement-6791 February 6, 2026 04:54
@JonathanLEvans
Copy link

JonathanLEvans commented Feb 6, 2026

Hi @decsecre583,

Thank you for your contribution. However, I am unable to find 7-Zip in one of our supported ecosystems. Could you provide a link to where you found it in one of the package systems?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants