PatchSiren

Codehaus Plexus CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Codehaus Plexus CVE published 2026-03-25

CVE-2025-67030

A Directory Traversal vulnerability exists in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before version 3.6.1 and 4.0.3. This allows an attacker to potentially execute arbitrary code. The vulnerability has significant operational impacts, including potential arbitrary code execution, and defenders should prioritize verification, updates, and compensating controls. Affected d [truncated]