Vulnerability Report: GO-2025-3605
- CVE-2025-3445, GHSA-7vpp-9cxj-q8gv
- Affects: github.com/mholt/archiver, github.com/mholt/archiver/v3
- Published: Aug 05, 2025
Vulnerable to Path Traversal via Crafted ZIP File in github.com/mholt/archiver
For detailed information about this vulnerability, visit https://github.com/advisories/GHSA-7vpp-9cxj-q8gv.
Affected Modules
-
PathGo Versions
-
all versions, no known fixed
-
all versions, no known fixed
Aliases
References
- https://github.com/advisories/GHSA-7vpp-9cxj-q8gv
- https://github.com/mholt/archiver/commit/fea250ac6eacd56f90a82fbe2481cfdbb9a1bbd1
- https://github.com/mholt/archiver/issues/267
- https://vuln.go.dev/ID/GO-2025-3605.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.