CVE-2025-55188 affects 7-Zip versions before 25.01. The vulnerability is caused by improper handling of symbolic links during archive extraction. A specially crafted archive can abuse symlink processing so that extracted content is written outside the intended extraction directory, resulting in an arbitrary file write / directory traversal condition during decompression. Public discussion and proof-of-concept material indicate the issue can be triggered via a symbolic-link-based archive extraction attack and may, in some scenarios, lead to execution of attacker-controlled code if written files land in executable or auto-loaded locations.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept (PoC) for CVE-2025-55188, a vulnerability in 7-Zip (and potentially similar archive extraction tools) that allows arbitrary file write via crafted archive files containing symlinks and/or hardlinks. The repository is organized into two main directories: - `poc_lnk`: Demonstrates the 'hardlink method' for exploitation, with Python scripts that generate tar archives capable of writing files outside the extraction directory. Notably, `rce.py` creates a tarball that, when extracted on Windows, writes a batch file to the Startup folder, leading to code execution on next login. - `poc_vrt`: Demonstrates the 'extraction root abuse method', with Python and Bash scripts for tar, zip, 7z, and rar formats. For example, `rce.py` creates a tarball that writes to `.bash_aliases` on Linux, enabling code execution on next shell startup. Other scripts show arbitrary file write to locations like `../file.txt`. The PoCs target both Windows and Linux platforms and show how an attacker can achieve code execution by tricking a user into extracting a malicious archive. The payloads are crafted archives, and the attack vector is local (user-assisted, via archive extraction). The repository contains both code to generate the malicious archives and the resulting archive files themselves.
This repository provides a proof-of-concept exploit for CVE-2025-55188, a vulnerability in 7-Zip versions prior to 25.01 that allows arbitrary file overwrite via symlink traversal during archive extraction. The repository contains two files: a README.md with detailed usage instructions and vulnerability explanation, and exploit.sh, a Bash script that automates the creation of a malicious .7z archive. The script takes a payload file (attacker-controlled content), a target file path (the file to overwrite, such as '../../.ssh/authorized_keys'), and outputs a crafted archive. When a victim extracts this archive with a vulnerable 7-Zip version, the payload overwrites the target file, potentially leading to code execution or unauthorized access. The exploit is a local attack vector, requiring the victim to extract the archive. No network endpoints are involved, but file paths such as '.bashrc' and '.ssh/authorized_keys' are notable targets.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.