HIGH
GHSA-5458-7hh9-v7p4
pf4j is vulnerable to Path Traversal or Zip Slip attack through improper handling of zip entry names
Quick fix
GHSA-5458-7hh9-v7p4 — org.pf4j:pf4j: upgrade to the fixed version with the command below.
# pom.xml: bump <version>3.14.1</version> for org.pf4j:pf4jDetails
pf4j before 20c2f80 has a path traversal vulnerability in the extract() function of Unzip.java, where improper handling of zip entry names can allow directory traversal or Zip Slip attacks, due to a lack of proper path normalization and validation.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.pf4j:pf4j
Introduced in:
0Fixed in: 3.14.1Fix
# pom.xml: bump <version>3.14.1</version> for org.pf4j:pf4jReferences
- https://nvd.nist.gov/vuln/detail/CVE-2025-70952[ADVISORY]
- https://github.com/pf4j/pf4j/issues/618[WEB]
- https://github.com/pf4j/pf4j/issues/623[WEB]
- https://github.com/pf4j/pf4j/commit/20c2f80089d1ea779e22c2de5f109a0bce4e1b14[WEB]
- https://gist.github.com/weaver4VD/410f23adb24ef5f5077f021f4393e705[WEB]
- https://github.com/pf4j/pf4j[PACKAGE]