Summary
Apply the patch to your DSpace
If at all possible, we recommend upgrading your DSpace site based on the upgrade instructions. However, if you are unable to do so, you can manually apply the above patches to your DSpace backend as follows:
- Download the appropriate patch file to the machine where DSpace backend is running
- From the
[dspace-src]folder, apply the patch, e.g.git apply [name-of-file].patch - Now, update your DSpace site (based loosely on the Upgrade instructions). This generally involves three steps:
- Rebuild DSpace, e.g.
mvn -U clean package(This will recompile all DSpace backend code) - Redeploy DSpace, e.g.
ant update(This will copy all newly built code to your installation directory). Depending on your setup you also may need to copy the updated "server" webapp over to your Tomcat webapps folder. - Restart Tomcat (or runnable JAR)
- Rebuild DSpace, e.g.
Workarounds
Patching the system is the recommended fix. It is not possible to fully protect your system via workarounds.
That said, until you are able to patch your system or upgrade, you can apply these best practices:
- Administrators must carefully inspect any SAF archives (they did not construct themselves) before importing, paying close attention to the
contentsfile to validate it does not reference files outside of the SAF archives. - If SAF archives are too large to manually inspect, you should avoid importing them until your site is patched.
Credits
Discovered & reported by Marcin Miłosz (@MMilosz) of PCG Academia
Code fix developed by Marcin Miłosz of PCG Academia and Kim Shepherd (@kshepherd) of The Library Code
For more information
- Path Traversal Vulnerability explained
- If you have any questions or comments about this advisory, please contact us at [email protected]
Impact
A path traversal vulnerability is possible during the import of an archive (in Simple Archive Format), either from command-line (./dspace import command) or from the "Batch Import (Zip)" user interface feature. This vulnerability likely impacts all versions of DSpace 1.x <= 7.6.3, 8.0 <= 8.1, and 9.0.
An attacker may craft a malicious Simple Archive Format (SAF) package where the contents file references any system files (using relative traversal sequences) which are readable by the Tomcat user. If such a package is imported, this will result in sensitive content disclose, including retrieving arbitrary files or configurations from the server where DSpace is running.
The Simple Archive Format (SAF) importer / Batch Import (Zip) is only usable by site administrators (from user interface / REST API) or system administrators (from command-line). Therefore, to exploit this vulnerability, the malicious payload would have to be provided by an attacker and trusted by an administrator (who would trigger the import).
- The most severe practical impact is a case where an attacker obtains DSpace administrator credentials and uses the Batch Import feature with a malicious SAF archive to expose sensitive local files readable by the Tomcat user.
- An attacker without administrative credentials might use some other tactic to convince an administrator to import a malicious SAF archive they have supplied.
Input manipulates file paths to reach files outside the intended directory, such as configuration or credential files. Typical impact: unauthorized file read or write outside the intended directory.
CVE-2025-53622 has a CVSS score of 5.2 (Medium). The vector is network-reachable, high privileges required, and user interaction required. A CVSS score reflects the worst-case severity of the vulnerability, not your specific exposure. Whether this affects your application depends on whether the vulnerable code is present and reachable in your environment. A fixed version is available (7.6.4, 8.2, 9.1); upgrading removes the vulnerable code path.
Affected versions
Security releases
Kodem intelligence
Severity tells you how bad this could be in the worst case. It does not tell you whether you are exposed. Exploitability and impact are functions of runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A vulnerable package can sit in your dependency tree and never run.
Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter. Kodem's runtime-powered SCA identifies whether this CVE is reachable in your applications.
Remediation advice
The fix is included in DSpace 7.6.4, 8.2 and 9.1. Please upgrade to one of these versions.
If you cannot upgrade immediately, it is possible to manually patch your DSpace backend. (No changes are necessary to the frontend.) A pull request exists which can be used to patch systems running DSpace 7.6.x, 8.x or 9.0. This pull request provides validation checks of paths in the contents file of an SAF package to ensure it does not reference any files outside of the SAF package.
- Pull request for 7.x: https://github.com/DSpace/DSpace/pull/11036 (Downloadable patch file)
- Pull request for 8.x: https://github.com/DSpace/DSpace/pull/11037 (Downloadable patch file)
- Pull request for 9.0: https://github.com/DSpace/DSpace/pull/11038 (Downloadable patch file)
Frequently Asked Questions
- What is CVE-2025-53622? CVE-2025-53622 is a medium-severity path traversal vulnerability in org.dspace:dspace-api (maven), affecting versions < 7.6.4. It is fixed in 7.6.4, 8.2, 9.1. Input manipulates file paths to reach files outside the intended directory, such as configuration or credential files.
- How severe is CVE-2025-53622? CVE-2025-53622 has a CVSS score of 5.2 (Medium). This score reflects the worst-case severity of the vulnerability, not your specific exposure. Whether it represents real risk in your environment depends on whether the vulnerable code is present and reachable.
- Which versions of org.dspace:dspace-api are affected by CVE-2025-53622? org.dspace:dspace-api (maven) versions < 7.6.4 is affected.
- Is there a fix for CVE-2025-53622? Yes. CVE-2025-53622 is fixed in 7.6.4, 8.2, 9.1. Upgrade to this version or later.
- Is CVE-2025-53622 exploitable, and should I be worried? Whether CVE-2025-53622 is exploitable in your environment depends on whether the vulnerable code is present and reachable. A CVSS score is a worst-case rating; it does not account for your specific deployment, configuration, or usage patterns. Kodem, an Intelligent Application Security platform, uses runtime intelligence to show which vulnerabilities actually execute in production, so you can focus on the ones that represent real risk. Get a demo
- What actually determines whether CVE-2025-53622 is exploitable, and how bad it is? Exploitability and impact are not fixed properties of a CVE. They depend on runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A high CVSS score on a dependency that never runs is not the same as real risk. Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter.
- How do I fix CVE-2025-53622?
- Upgrade
org.dspace:dspace-apito 7.6.4 or later - Upgrade
org.dspace:dspace-apito 8.2 or later - Upgrade
org.dspace:dspace-apito 9.1 or later
- Upgrade