Low severity3.6NVD Advisory· Published Aug 8, 2025· Updated Jun 17, 2026
CVE-2025-55188
CVE-2025-55188
Description
7-Zip before 25.01 does not always properly handle symbolic links during extraction.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
13- lunbun.dev/blog/cve-2025-55188/nvdExploitThird Party Advisory
- youtu.be/sWT6M1cfnwMnvdExploit
- www.openwall.com/lists/oss-security/2025/08/09/1nvdMailing ListThird Party Advisory
- github.com/ip7z/7zip/compare/25.00...25.01nvdProduct
- github.com/ip7z/7zip/releases/tag/25.01nvdRelease Notes
- sourceforge.net/p/sevenzip/discussion/45797/thread/da14cd780b/nvdProduct
- www.openwall.com/lists/oss-security/2025/08/09/1nvd
- www.openwall.com/lists/oss-security/2025/08/10/1nvd
- www.openwall.com/lists/oss-security/2025/08/13/1nvd
- www.openwall.com/lists/oss-security/2025/10/12/2nvd
- www.openwall.com/lists/oss-security/2025/10/16/7nvd
- www.vicarius.io/vsociety/posts/cve-2025-55188-detect-7-zip-vulnerable-versionnvd
- www.vicarius.io/vsociety/posts/cve-2025-55188-mitigate-7-zip-vulnerabilitynvd
News mentions
1- Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-MCISA ICS Advisories