← back
CVE-2025-10284criticalCWE-22

Improper Archive Extraction in unarchive Enables RCE

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.6epss 0.7%
exploitation probability
0.7%top 48% of all CVEs
observed exploitation
nono source reports it
BBOT's unarchive module could be abused by supplying malicious archives files and when extracted can then perform an arbitrary file write, resulting in remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected products
BLSOPS, LLC · bbot