CVE-2025-0851 is a path traversal vulnerability in Deep Java Library (DJL) affecting the archive extraction routines ZipUtils.unzip and TarUtils.untar on all platforms. The flaw allows a crafted ZIP or TAR archive containing traversal sequences in file paths to escape the intended extraction directory and cause files to be written to attacker-controlled arbitrary locations on the filesystem. This is a classic archive extraction traversal issue in which insufficient validation or sanitization of archive entry paths permits writes outside the target directory.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept (POC) for CVE-2025-0851, a file traversal vulnerability in the Deep Java Library's archive extraction utility. The vulnerability allows an attacker to craft tar or zip archives containing files with absolute or traversal paths (e.g., C:\Windows\System32\config\TEST). When such an archive is extracted on Windows, the vulnerable code (using dest.resolve(name).toAbsolutePath()) fails to properly sanitize the file path, resulting in files being written outside the intended extraction directory. The repository contains a README.md explaining the vulnerability and exploitation steps, and a test.tar file that, when extracted by the vulnerable library, writes a file to C:\Windows\System32\config\TEST. There is no exploit code in the repository, only the crafted archive and documentation. The exploit demonstrates a local attack vector, requiring the attacker to supply a malicious archive to a system using the vulnerable extraction utility.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.