← Back to CVE List
Vulnerability Intelligence Report
Zip slip vulnerability in Juju

CVE-2025-53513

The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on the controller to upload a charm. Uploading a malicious charm that exploits a Zip Slip vulnerability could allow an attacker to gain access to a machine running a unit through the affected charm.

No Active Exploit Signals
CVSS Base Score
8.8
HIGH
Exploitability:2.9
Impact Score:5.9
EPSS Probability:0.65%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
No affected products specified.

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.647%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityCanonical Ltd. · Vendor · UK
Reserved2025-07-02T08:52:42
Published2025-07-08T16:57:06
Last Updated2025-07-09T14:00:10

LINK COPIED TO CLIPBOARD