https://seclists.org/oss-sec/2025/q3/89: CVE-2025-55188: 7-Zip: Arbitrary file write on extraction, may lead to code execution
Published Aug 11, 2025
·Updated
Affected Software
1 affected component
7-Zip 7-Zip
Frequently Asked Questions
1
What is the severity of CVE-2025-55188?
CVE-2025-55188 has been classified as a high severity vulnerability due to its potential to allow arbitrary file write and possible code execution.
2
How do I fix CVE-2025-55188?
To mitigate CVE-2025-55188, users should update to the latest version of 7-Zip that addresses this vulnerability.
3
What type of vulnerability is CVE-2025-55188?
CVE-2025-55188 is an arbitrary file write vulnerability that could lead to code execution when extracting compressed files.
4
Who is affected by CVE-2025-55188?
Any user of 7-Zip versions prior to the patch for CVE-2025-55188 is potentially affected by this vulnerability.
5
What does CVE-2025-55188 exploit?
CVE-2025-55188 exploits the way 7-Zip handles symbolic links during the extraction process.