-
Notifications
You must be signed in to change notification settings - Fork 931
Closed
Labels
5 - ReleasedDependency ChangeIf a dependency or bundled binaries are added, removed or updated.If a dependency or bundled binaries are added, removed or updated.Priority_HIGHSecurity
Milestone
Description
Checklist
- I have verified this is the correct repository for opening this issue.
- I have verified no other issues exist related to my request.
Is Your Feature Request Related To A Problem? Please describe.
There is a CVE (CVE-2025-55188) associated with 7-zip, which has been addressed in version 25.01.
Describe The Solution. Why is it needed?
Update the embedded 7-zip binaries to the latest version, and ship a new release of Chocolatey CLI.
Additional Context
See https://nvd.nist.gov/vuln/detail/CVE-2025-55188 and https://github.com/ip7z/7zip/releases
Related Issues
luigilink, t-h-e-c-h-e-f, jmarshbdo and gep13
Metadata
Metadata
Assignees
Labels
5 - ReleasedDependency ChangeIf a dependency or bundled binaries are added, removed or updated.If a dependency or bundled binaries are added, removed or updated.Priority_HIGHSecurity