ZDI-25-254: Allegra extractFileFromZip Directory Traversal Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Authentication is required to exploit this vulnerability. The specific flaw exists within the implementation of the extractFileFromZip method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current process.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2025-3485.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-254?
The ZDI-25-254 vulnerability has a CVSS rating of 7.2, indicating a high severity.
How do I fix ZDI-25-254?
To fix ZDI-25-254, ensure you are running the latest version of Allegra where the vulnerability has been patched.
What type of attack does ZDI-25-254 involve?
ZDI-25-254 allows remote attackers to execute arbitrary code on affected installations of Allegra.
Is authentication required to exploit ZDI-25-254?
Yes, authentication is required to exploit the ZDI-25-254 vulnerability.
Which software is affected by ZDI-25-254?
The ZDI-25-254 vulnerability affects specific installations of Allegra.