CVE-2025-53632 Details
Description
Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. When decoding a scenario (i.e. a zip archive), the path of the file to write is not checked, potentially leading to zip slips. Exploitation does not require authentication nor authorization, so anyone can exploit it. It should nonetheless not be exploitable as it is highly recommended to bury Chall-Manager deep within the infrastructure due to its large capabilities, so no users could reach the system. Patch has been implemented by commit 47d188f and shipped in v0.1.4.
A zip slip vulnerability has been identified in Chall-Manager, a platform-agnostic system that starts Challenges on Demand for players. The issue arises during the decoding of scenarios from zip archives, where the file path for extraction is not properly validated. This oversight can lead to zip slip attacks, allowing files to be extracted outside of the intended directory. The vulnerability exists in versions prior to 0.1.4 and can be exploited by anyone, without the need for authentication or authorization. Although it is recommended to keep Chall-Manager hidden within the infrastructure due to its extensive capabilities, this vulnerability could still be exploited if the system is exposed.
Users can upgrade to Chall-Manager version 0.1.4 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ctfer-io chall-manager | < 0.1.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 14, 2025 | Initial Analysis | [email protected] |
| Jul 10, 2025 | New CVE Received | [email protected] |