CVE-2025-63371

7.5

Milos Paripovic · OneCommander

Milos Paripovic OneCommander 3.102.0.0 is vulnerable to directory traversal via the ZIP file processing component, allowing unauthorized file access.

Executive summary

A directory traversal vulnerability in OneCommander 3.102.0.0 allows unauthenticated attackers to access sensitive files via malicious ZIP archives.

Vulnerability

This is a directory traversal vulnerability located in the ZIP file extraction and handling component. It allows an unauthenticated attacker to escape the intended directory boundaries during archive decompression.

Business impact

The ability to perform directory traversal poses a significant risk to data confidentiality, as attackers can read arbitrary files on the host system where OneCommander is operating. With a CVSS score of 7.5, this high-severity flaw could lead to the exposure of sensitive configuration files, credentials, or personal user data. Failure to remediate this issue may result in unauthorized system access and potential compromise of the local environment.

Remediation

Immediate Action: Users should check the vendor website for updates and apply the latest security patch provided by Milos Paripovic as soon as it becomes available.

Proactive Monitoring: Review file system access logs for anomalous read patterns or attempts to access files outside of expected working directories.

Compensating Controls: Avoid opening untrusted or unsolicited ZIP archives within the OneCommander application until a verified patch has been applied to the software.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the nature of directory traversal vulnerabilities, this issue presents a clear risk to local file integrity. Security teams should prioritize monitoring for software updates from the vendor and ensure that users are advised against processing untrusted archive files until the specific version identified as vulnerable is secured.

Sources