CVE-2025-54386
In versions 2.11.27 and below, 3.0.0 through 3.4.4 and 3.5.0-rc1, a path traversal vulnerability was discovered in WASM Traefik’s plugin installation mechanism.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.10%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Traefik is an HTTP reverse proxy and load balancer. In versions 2.11.27 and below, 3.0.0 through 3.4.4 and 3.5.0-rc1, a path traversal vulnerability was discovered in WASM Traefik’s plugin installation mechanism. By supplying a maliciously crafted ZIP archive containing file paths with ../ sequences, an attacker can overwrite arbitrary files on the system outside of the intended plugin directory. This can lead to remote code execution (RCE), privilege escalation, persistence, or denial of service. This is fixed in versions 2.11.28, 3.4.5 and 3.5.0.
- CVSS 4.0
- 7.3 HIGHCVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 1.10% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22, CWE-30
- Affected
- traefik/traefik
- Source
- security-advisories@github.com
References
- https://github.com/traefik/plugin-service/pull/71Patch
- https://github.com/traefik/plugin-service/pull/72Patch
- https://github.com/traefik/traefik/commit/5ef853a0c53068f69a6c229a5815a0dc6e0a8800Patch
- https://github.com/traefik/traefik/pull/11911Patch
- https://github.com/traefik/traefik/releases/tag/v2.11.28Release Notes
- https://github.com/traefik/traefik/security/advisories/GHSA-q6gg-9f92-r9wgVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.