Path traversal in magento-lts - CVE-2026-25525
Published: April 20, 2026
magento-lts
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to path traversal in the Dataflow module file import handling when processing the files parameter. A remote privileged user can supply a crafted path traversal sequence to disclose sensitive information.
The issue can be exploited through the admin panel when running or modifying a Dataflow import profile.