GHSA-wx3r-v6h7-frjp · Severity: critical · Ecosystem: pip — internetarchive Vulnerable to Directory Traversal in File.download()
internetarchive is a Python and Command-Line Interface to Archive.org In versions 5.5.0 and below, there is a directory traversal (path traversal) vulnerability in the File.download() method of the internetarchive library. The file.download() method does not properly sanitize user-supplied filenames or validate the final download path. A maliciously crafted filename could contain path traversal sequences (e.g., ../../../../windows/system32/file.txt) or illegal characters that, when processed, would cause the file to be written outside of the intended target directory. An attacker could potentially overwrite critical system files or application configuration files, leading to a denial of service, privilege escalation, or remote code execution, depending on the context in which the library is used. The vulnerability is particularly critical for users on Windows systems, but all operating systems are affected. This issue is fixed in version 5.5.1.
Conclusion & alert: CVE-2025-58438 is rated High Risk (69.3/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 3.85%). Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-23 | 3.03% | 3.85% | +0.82% |
| 2 | 2026-05-12 | 2.80% | 3.03% | +0.23% |
| 3 | 2026-04-12 | — | 2.80% | — |
Full EPSS history (21 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.4 | 4.0 | CRITICAL |
|
— | — | [email protected] |
GHSA-wx3r-v6h7-frjp · Severity: critical · Ecosystem: pip — internetarchive Vulnerable to Directory Traversal in File.download()
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2025-58438 not yet assigned priority: Debian including 1 source packages (python-internetarchive), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2025-58438 |
ubuntu
|
medium | CVE-2025-58438 medium priority: Ubuntu including 1 source packages (python-internetarchive), 6 status rows across 6 suites (focal, jammy, noble, plucky, questing, upstream): released 5, ignored 1. | https://ubuntu.com/security/CVE-2025-58438 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||