pf4j before 20c2f80 has a path traversal vulnerability in the extract() function of Unzip.java, where improper handling of zip entry names can allow directory traversal or Zip Slip attacks, due to a lack of proper path normalization and validation.
{
"cna_assigner": "mitre",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "pf4j"
},
{
"fixed": "20c2f80"
}
],
"source": "DESCRIPTION"
}
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/70xxx/CVE-2025-70952.json"
}{
"cpe": "cpe:2.3:a:pf4j_project:pf4j:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "3.14.1"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"2026-07-21T23:25:23Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-70952.json"
[
{
"signature_type": "Function",
"target": {
"file": "pf4j/src/main/java/org/pf4j/util/Unzip.java",
"function": "extract"
},
"deprecated": false,
"digest": {
"length": 1011.0,
"function_hash": "253057656720980051171116464833318622413"
},
"signature_version": "v1",
"source": "https://github.com/pf4j/pf4j/commit/20c2f80089d1ea779e22c2de5f109a0bce4e1b14",
"id": "CVE-2025-70952-1f6babde"
},
{
"signature_type": "Line",
"target": {
"file": "pf4j/src/main/java/module-info.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"256001070061343481858270498874984267146",
"227782772851238445579653647503076655356",
"323697229540984549511580650023475231899",
"90877395449385225515031197398092003800",
"278221398673693210312615913745845636195",
"183820035221782670768511872410962893925"
]
},
"signature_version": "v1",
"source": "https://github.com/pf4j/pf4j/commit/20c2f80089d1ea779e22c2de5f109a0bce4e1b14",
"id": "CVE-2025-70952-419d1123"
},
{
"signature_type": "Function",
"target": {
"file": "pf4j/src/test/java/org/pf4j/util/UnzipTest.java",
"function": "createMaliciousZipFile"
},
"deprecated": false,
"digest": {
"length": 389.0,
"function_hash": "237090949863444508017308368234914472565"
},
"signature_version": "v1",
"source": "https://github.com/pf4j/pf4j/commit/20c2f80089d1ea779e22c2de5f109a0bce4e1b14",
"id": "CVE-2025-70952-59773be3"
},
{
"signature_type": "Line",
"target": {
"file": "pf4j/src/main/java/org/pf4j/util/Unzip.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"171444151610414376169025138311160781884",
"17862288441120938289186277816305460977",
"317487300280540671116132564149158928197",
"13100310458176886895497552212336934162",
"243097082900672314807692765700979873810",
"76740222291344701530372902407297795141",
"55979515125495199922207159585312026318",
"3475553176018127277104620368359700805",
"188387110822814031866990973580258874114",
"172025312303737851897134609223214976561",
"208787153944094720582174278084095764495",
"289577955964086845752602735824572019244",
"142995542566173887383596354845276332261",
"116249538268061424828673859167298288225",
"28013072966596356403481590611578683258",
"301870869692998657074686892099287595625",
"69123628957505696631708598921152657664",
"288319528762119932998504260960124657727",
"189186283645988486573226202906626782203"
]
},
"signature_version": "v1",
"source": "https://github.com/pf4j/pf4j/commit/20c2f80089d1ea779e22c2de5f109a0bce4e1b14",
"id": "CVE-2025-70952-5f6e544e"
},
{
"signature_type": "Function",
"target": {
"file": "pf4j/src/test/java/org/pf4j/util/UnzipTest.java",
"function": "zipSlip"
},
"deprecated": false,
"digest": {
"length": 362.0,
"function_hash": "56402618767251861640903557912081446268"
},
"signature_version": "v1",
"source": "https://github.com/pf4j/pf4j/commit/20c2f80089d1ea779e22c2de5f109a0bce4e1b14",
"id": "CVE-2025-70952-94b877c5"
},
{
"signature_type": "Line",
"target": {
"file": "pf4j/src/test/java/org/pf4j/util/UnzipTest.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"64706012557220039395780267090851691857",
"41583390673326685001982352233348259564",
"304229133156415490843266377955443778356",
"231874775262152187627481872769280813847",
"15033450737081878184934422295811637871",
"203093042409316608141538743001622867994",
"21302151147656012257120660422701802926",
"334475296513030544086183727315743699247",
"14935062281343620622037640760017285112",
"67906798423014549328165995561586858863",
"122081789489064191759254149295382610041",
"309027612789748892557890844624512187952",
"5999120656859378079634142338892070139",
"319672512529121040334378601665620174908"
]
},
"signature_version": "v1",
"source": "https://github.com/pf4j/pf4j/commit/20c2f80089d1ea779e22c2de5f109a0bce4e1b14",
"id": "CVE-2025-70952-9da21be9"
}
]