CVE-2025-9918

A Path Traversal vulnerability in the archive extraction component in Google SecOps SOAR Server (versions 6.3.54.0, 6.3.53.2, and all prior versions) allows an authenticated attacker with permissions to import Use Cases to achieve Remote Code Execution (RCE) via uploading a malicious ZIP archive containing path traversal sequences.
CVSS

No CVSS.

Configurations

No configuration.

History

11 Sep 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-11 08:15

Updated : 2025-09-11 17:14


NVD link : CVE-2025-9918

Mitre link : CVE-2025-9918

CVE.ORG link : CVE-2025-9918


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')