← back
CVE-2026-25707

Handcrafted repo metadata may cause arbitrary local files to be overwritten by libzypp

CVSS 8.8 HIGHCWE-23
Vexday Risk Score
18Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.8EPSS KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
29 Jun 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
SUSE · libzypp

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →