7-Zip Symbolic Link Extraction Vulnerability - Vulnerability

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
December 25, 2025
Last Seen
December 25, 2025

7-Zip Symbolic Link Extraction Vulnerability is a vulnerability tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed December 25, 2025; most recent activity December 25, 2025.

Overview

The 7-Zip Symbolic Link Extraction Vulnerability is a flaw in the 7-Zip archive tool where crafted archives can abuse symbolic links during extraction to access or overwrite files outside the intended extraction directory. This can lead to path traversal, arbitrary file writes, or information disclosure, depending on environment and permissions. Its significance stems from 7-Zip's wide usage across platforms, potentially enabling impact across many users and workflows that involve extracting archives.

Related Threat Clusters

Recent Intelligence Reports

  • Fedora 43: retroarch Critical Buffer Overflow Issue FEDORA-2025 — Linuxsecurity · December 25, 2025

CVSS v3.1 Breakdown