CVE-2025-53622: DSpace has path traversal vulnerability in Simple Archive Format (SAF) package import via contents file

Published Jul 15, 2025
·
Updated

Impact

A path traversal vulnerability is possible during the import of an archive (in Simple Archive Format), either from command-line (./dspace import command) or from the "Batch Import (Zip)" user interface feature. This vulnerability likely impacts all versions of DSpace 1.x <= 7.6.3, 8.0 <= 8.1, and 9.0.

An attacker may craft a malicious Simple Archive Format (SAF) package where the contents file references any system files (using relative traversal sequences) which are readable by the Tomcat user. If such a package is imported, this will result in sensitive content disclose, including retrieving arbitrary files or configurations from the server where DSpace is running.

The Simple Archive Format (SAF) importer / Batch Import (Zip) is only usable by site administrators (from user interface / REST API) or system administrators (from command-line). Therefore, to exploit this vulnerability, the malicious payload would have to be provided by an attacker and trusted by an administrator (who would trigger the import). The most severe practical impact is a case where an attacker obtains DSpace administrator credentials and uses the Batch Import feature with a malicious SAF archive to expose sensitive local files readable by the Tomcat user. An attacker without administrative credentials might use some other tactic to convince an administrator to import a malicious SAF archive they have supplied.

Patches

The fix is included in DSpace 7.6.4, 8.2 and 9.1. Please upgrade to one of these versions.

If you cannot upgrade immediately, it is possible to manually patch your DSpace backend. (No changes are necessary to the frontend.) A pull request exists which can be used to patch systems running DSpace 7.6.x, 8.x or 9.0. This pull request provides validation checks of paths in the contents file of an SAF package to ensure it does not reference any files outside of the SAF package. Pull request for 7.x: https://github.com/DSpace/DSpace/pull/11036 (Downloadable patch file) Pull request for 8.x: https://github.com/DSpace/DSpace/pull/11037 (Downloadable patch file) Pull request for 9.0: https://github.com/DSpace/DSpace/pull/11038 (Downloadable patch file)

Apply the patch to your DSpace If at all possible, we recommend upgrading your DSpace site based on the upgrade instructions. However, if you are unable to do so, you can manually apply the above patches to your DSpace backend as follows: 1. Download the appropriate patch file to the machine where DSpace backend is running 2. From the [dspace-src] folder, apply the patch, e.g. git apply [name-of-file].patch 3. Now, update your DSpace site (based loosely on the Upgrade instructions). This generally involves three steps: 1. Rebuild DSpace, e.g. mvn -U clean package (This will recompile all DSpace backend code) 2. Redeploy DSpace, e.g. ant update (This will copy all newly built code to your installation directory). Depending on your setup you also may need to copy the updated "server" webapp over to your Tomcat webapps folder. 3. Restart Tomcat (or runnable JAR)

Workarounds Patching the system is the recommended fix. It is not possible to fully protect your system via workarounds.

That said, until you are able to patch your system or upgrade, you can apply these best practices: Administrators must carefully inspect any SAF archives (they did not construct themselves) before importing, paying close attention to the contents file to validate it does not reference files outside of the SAF archives. If SAF archives are too large to manually inspect, you should avoid importing them until your site is patched.

Credits Discovered & reported by Marcin Miłosz (@MMilosz) of PCG Academia Code fix developed by Marcin Miłosz of PCG Academia and Kim Shepherd (@kshepherd) of The Library Code

For more information Path Traversal Vulnerability explained If you have any questions or comments about this advisory, please contact us at security@dspace.org

Other sources

DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.4, 8.2, and 9.1, a path traversal vulnerability is possible during the import of an archive (in Simple Archive Format), either from command-line (./dspace import command) or from the "Batch Import (Zip)" user interface feature. An attacker may craft a malicious Simple Archive Format (SAF) package where the contents file references any system files (using relative traversal sequences) which are readable by the Tomcat user. If such a package is imported, this will result in sensitive content disclose, including retrieving arbitrary files or configurations from the server where DSpace is running. The Simple Archive Format (SAF) importer / Batch Import (Zip) is only usable by site administrators (from user interface / REST API) or system administrators (from command-line). Therefore, to exploit this vulnerability, the malicious payload would have to be provided by an attacker and trusted by an administrator (who would trigger the import). The fix is included in DSpace 7.6.4, 8.2 and 9.1. For those who cannot upgrade immediately, it is possible to manually patch the DSpace backend. (No changes are necessary to the frontend.) A pull request exists which can be used to patch systems running DSpace 7.6.x, 8.x or 9.0. Although it is not possible to fully protect the system via workarounds, one may can apply a best practice. Administrators must carefully inspect any SAF archives (they did not construct themselves) before importing, paying close attention to the contents file to validate it does not reference files outside of the SAF archives.

MITRE

Affected Software

4 affected componentsFixes available
DSpace DSpace<7.6.4, <8.2, <9.1
maven/org.dspace:dspace-api>=9.0<9.1
9.1
maven/org.dspace:dspace-api>=8.0<8.2
8.2
maven/org.dspace:dspace-api<7.6.4
7.6.4

Event History

Jul 15, 2025
CVE Published
via MITRE·02:47 PM
Data Sourced
via MITRE·02:47 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·06:05 PM
Data Sourced
via GitHub·06:05 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-53622?

CVE-2025-53622 is classified as a moderate severity path traversal vulnerability affecting DSpace versions prior to 7.6.4, 8.2, and 9.1.

2

How do I fix CVE-2025-53622?

To resolve CVE-2025-53622, upgrade to DSpace version 7.6.4, 8.2, or 9.1 or a later release.

3

What systems are affected by CVE-2025-53622?

CVE-2025-53622 affects DSpace versions prior to 7.6.4, 8.2, and 9.1 when importing archives.

4

Can CVE-2025-53622 lead to unauthorized access?

Yes, CVE-2025-53622 can allow attackers to potentially access unauthorized files on the server due to path traversal.

5

When was CVE-2025-53622 reported?

CVE-2025-53622 was reported as a security vulnerability prior to the release of the fixed versions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203