CVE-2025-4748: Absolute path traversal in zip:unzip/1,2

Over the weekend the first CVE from the Erlang Ecosystem Foundation CNA was posted:

If you or your dependencies use :zip.unzip/1,2 then you should upgrade to OTP 28.0.1, OTP 27.3.4.1 and OTP 26.2.5.13.

11 Likes