A Path Traversal vulnerability in the archive extraction component in Google SecOps SOAR Server (versions 6.3.54.0, 6.3.53.2, and all prior versions) allows an authenticated attacker with permissions to import Use Cases to achieve Remote Code Execution (RCE) via uploading a malicious ZIP archive containing path traversal sequences.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 11 Sep 2025 07:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A Path Traversal vulnerability in the archive extraction component in Google SecOps SOAR Server (versions 6.3.54.0, 6.3.53.2, and all prior versions) allows an authenticated attacker with permissions to import Use Cases to achieve Remote Code Execution (RCE) via uploading a malicious ZIP archive containing path traversal sequences. | |
Title | Zip Slip in Google SecOps SOAR allows for Remote Code Execution | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GoogleCloud
Published:
Updated: 2025-09-11T07:37:50.010Z
Reserved: 2025-09-03T10:53:44.603Z
Link: CVE-2025-9918

No data.

Status : Received
Published: 2025-09-11T08:15:40.057
Modified: 2025-09-11T08:15:40.057
Link: CVE-2025-9918

No data.

No data.