CVE-2025-49559: Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to modify limited data. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49559?
CVE-2025-49559 is considered a high severity vulnerability due to its potential to allow path traversal attacks.
How do I fix CVE-2025-49559?
To fix CVE-2025-49559, upgrade Adobe Commerce to version 2.4.9-alpha2 or later.
What types of attacks does CVE-2025-49559 enable?
CVE-2025-49559 could allow attackers to bypass security features and access restricted directories.
Who is affected by CVE-2025-49559?
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by CVE-2025-49559.
What details are known about the CVE-2025-49559 exploit?
CVE-2025-49559 is an improper limitation of pathname vulnerability that may allow unauthorized file access.