CVE-2025-32017: Umbraco has a Management API Vulnerability to Path Traversal With Authenticated Users
Impact Authenticated users to the Umbraco backoffice are able to craft management API request that exploit a path traversal vulnerability to upload files into a incorrect location.
Patches The issue affects Umbraco 14+ and is patched in 14.3.4 and 15.3.1.
Workarounds Umbraco supports the configuration of allowed and disallowed file extensions. Using these options to allow only necessary file extensions significantly reduces the scope of the vulnerability.
Other sources
Umbraco is a free and open source .NET content management system. Authenticated users to the Umbraco backoffice are able to craft management API request that exploit a path traversal vulnerability to upload files into a incorrect location. The issue affects Umbraco 14+ and is patched in 14.3.4 and 15.3.1.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32017?
CVE-2025-32017 is classified as a medium severity vulnerability affecting the Umbraco content management system.
How do I fix CVE-2025-32017?
To fix CVE-2025-32017, update Umbraco to the latest version beyond 15.3.1 where the vulnerability has been patched.
Who is affected by CVE-2025-32017?
Authenticated users of Umbraco versions 14.0 to 14.3.4 and 15.0 to 15.3.1 are affected by CVE-2025-32017.
What type of vulnerability is CVE-2025-32017?
CVE-2025-32017 is a path traversal vulnerability that allows file upload to incorrect locations via crafted API requests.
When was CVE-2025-32017 disclosed?
CVE-2025-32017 was disclosed in 2025, impacting various versions of the Umbraco CMS.