CVE-2025-53513: high-severity vulnerability in Canonical Juju
Zip slip vulnerability in Juju
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
A flaw in Juju's charm upload system allows any logged-in user to upload malicious files that can escape their intended directory and gain unauthorized access to machines. This happens because the system doesn't properly check file paths when extracting charm archives.
The /charms endpoint lacks sufficient authorization validation, permitting any authenticated user to upload charms. A Zip Slip vulnerability (CWE-24) in archive extraction allows path traversal, enabling attackers to write files outside the intended directory and achieve code execution on machines running vulnerable units. Exploitation requires only valid controller credentials.
In the same product, most dangerous first.