CVE 8.8 HIGH

Handcrafted repo metadata may cause arbitrary local files to be overwritten by libzypp_CVE-2026-25707

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.

AI Analysis

Relative path traversal vulnerability in libzypp allowing remote attackers to overwrite files on the system

Basic Information

ID CVE-2026-25707
Source suse
Published Jun 29, 2026 at 10:04

Affected Product

Vendor SUSE
Product libzypp
Affected Versions SUSE libzypp 0

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor SUSE
Product libzypp
Version before 17.38.10

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.