CVE-2025-24406: Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to a security feature bypass. An unauthenticated attacker could exploit this vulnerability to modify files that are stored outside the restricted directory. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24406?
CVE-2025-24406 is classified as a critical vulnerability due to its potential for a security feature bypass through path traversal.
How do I fix CVE-2025-24406?
To fix CVE-2025-24406, upgrade to Adobe Commerce versions 2.4.7 or later that have addressed this vulnerability.
What types of systems are affected by CVE-2025-24406?
CVE-2025-24406 affects Adobe Commerce versions up to 2.4.7-beta1 and includes earlier versions such as 2.4.6-p8 and 2.4.5-p10.
What can an attacker achieve by exploiting CVE-2025-24406?
By exploiting CVE-2025-24406, an attacker could bypass security features intended to protect restricted directories.
Is there a workaround for CVE-2025-24406 if I cannot upgrade?
Currently, there are no recommended workarounds for CVE-2025-24406; therefore, upgrading the software is strongly advised.