Relative Path Traversal in Rider - CVE-2025-43016
Published: April 25, 2025 / Updated: August 17, 2026
Vulnerability details
The vulnerability allows a remote user to overwrite arbitrary files.
The vulnerability exists due to path traversal in custom archive unpacker when unpacking a crafted archive during a remote debug session. A remote user can supply a specially crafted archive to overwrite arbitrary files.
Exploitation requires a remote debug session.