FlawAtlas
Search the atlas
CVE-2025-53633 High

Chall-Manager's scenario decoding process does not check for zip bombs in github.com/ctfer-io/chall-manager

Chall-Manager's scenario decoding process does not check for zip bombs in github.com/ctfer-io/chall-manager

Exploit probability 0.5%
Published July 28, 2025
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

8 explicit affected versions

Go github.com/ctfer-io/chall-manager
Go github.com/ctfer-io/chall-manager

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities GO-2025-3810

Chall-Manager's scenario decoding process does not check for zip bombs in github.com/ctfer-io/chall-manager

View original source
Open Source Vulnerabilities GHSA-r7fm-3pqm-ww5w

### Impact When decoding a scenario (i.e. a zip archive), the size of the decoded content is not checked, potentially leading to zip bombs decompression. Exploitation does not require authentication nor authorization, so anyone can exploit it. It should nonetheless not be exploitable as it is highly recommended to bury Chall-Manager deep within the infrastructure due to its large capabilities, so no users could reach the system. ### Patches Patch has been implemented by [commit `14042aa`](https://github.com/ctfer-io/chall-manager/commit/14042aa66a577caee777e10fe09adcf2587d20dd) and shipped in [`v0.1.4`](https://github.com/ctfer-io/chall-manager/releases/tag/v0.1.4). ### Workarounds No workaround exist. ### References N/A.

View original source
Open Source Vulnerabilities CVE-2025-53633

Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. When decoding a scenario (i.e. a zip archive), the size of the decoded content is not checked, potentially leading to zip bombs decompression. Exploitation does not require authentication nor authorization, so anyone can exploit it. It should nonetheless not be exploitable as it is highly recommended to bury Chall-Manager deep within the infrastructure due to its large capabilities, so no users could reach the system. Patch has been implemented by commit 14042aa and shipped in v0.1.4.

View original source

05 / REFERENCES

Further evidence