Relative Path Traversal in Umbraco CMS - CVE-2025-32017
Published: April 8, 2025 / Updated: May 5, 2026
Vulnerability details
The vulnerability allows a remote user to upload files into an incorrect location.
The vulnerability exists due to relative path traversal in the management API when handling crafted file upload requests. A remote user can send a specially crafted management API request to upload files into an incorrect location.
The issue is exploitable by authenticated users to the Umbraco backoffice.