{"id":"AZL-81041","summary":"CVE-2025-67030 affecting package plexus-utils for versions less than 3.3.0-5","details":"Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code","modified":"2026-08-30T05:26:50Z","published":"2026-03-25T18:16:25Z","upstream":["CVE-2025-67030"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-67030"}],"affected":[{"package":{"name":"plexus-utils","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/plexus-utils"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.3.0-5"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-81041.json"}}],"schema_version":"1.9.0"}