CVE-2025-53632 affects Chall-Manager, a platform-agnostic system used to start challenges on demand. The vulnerability is in the scenario decoding logic that processes a scenario ZIP archive. When extracting files from the archive, the application does not properly validate or constrain the output file paths before writing them to disk. As a result, a crafted archive containing directory traversal sequences in entry names can trigger a Zip Slip condition, allowing files to be written outside the intended extraction directory.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a working exploit for CVE-2025-53632, targeting ctfer-io Chall-Manager versions prior to 0.1.4. The exploit leverages the way Chall-Manager validates challenge scenarios using Pulumi: it allows an attacker to upload a scenario containing a tampered Pulumi binary. The exploit code (main.go) crafts a ZIP archive that replaces the expected Pulumi binary with a shell script containing attacker-supplied commands, followed by execution of the real Pulumi binary. This archive is then base64-encoded and submitted to the Chall-Manager gRPC API as a new challenge scenario. When the scenario is validated, the malicious script is executed on the host, granting the attacker arbitrary code execution. The repository includes Go code for the exploit, a minimal Pulumi scenario, and documentation. Notable endpoints include the default Chall-Manager port (8080), an example exfiltration endpoint (Beeceptor), and the URL for downloading the legitimate Pulumi binary. The exploit is operational and allows for arbitrary payloads, such as reverse shells or data exfiltration.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.