7-Zip Symbolic Link Extraction Vulnerability is a vulnerability tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed December 25, 2025; most recent activity December 25, 2025.
The 7-Zip Symbolic Link Extraction Vulnerability is a flaw in the 7-Zip archive tool where crafted archives can abuse symbolic links during extraction to access or overwrite files outside the intended extraction directory. This can lead to path traversal, arbitrary file writes, or information disclosure, depending on environment and permissions. Its significance stems from 7-Zip's wide usage across platforms, potentially enabling impact across many users and workflows that involve extracting archives.
A critical buffer overflow vulnerability has been identified in RetroArch, a frontend for the libretro API, affecting users of Fedora 43. The issue allows potential exploitation due to improper handling of…