Relative Path Traversal in Umbraco CMS - CVE-2025-32017

 

Relative Path Traversal in Umbraco CMS - CVE-2025-32017

Published: April 8, 2025 / Updated: May 5, 2026


Vulnerability identifier: #VU130185
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-32017
CWE-ID: CWE-23
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to upload files into an incorrect location.

The vulnerability exists due to relative path traversal in the management API when handling crafted file upload requests. A remote user can send a specially crafted management API request to upload files into an incorrect location.

The issue is exploitable by authenticated users to the Umbraco backoffice.


Affected software

Umbraco CMS

How to mitigate CVE-2025-32017

Install security update from vendor's website.

Umbraco CMS - addressed in versions 14.3.4, 15.3.1

External References

Related Security Bulletins