Relative Path Traversal in Umbraco CMS - CVE-2025-32017
Published: April 8, 2025 / Updated: May 5, 2026
Umbraco CMS
Detailed vulnerability description
The vulnerability allows a remote user to upload files into an incorrect location.
The vulnerability exists due to relative path traversal in the management API when handling crafted file upload requests. A remote user can send a specially crafted management API request to upload files into an incorrect location.
The issue is exploitable by authenticated users to the Umbraco backoffice.