CVE-2025-67288: Malicious File Upload
An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in the documentation) belongs to the system administrator who is implementing Umbraco CMS in their environment, not to Umbraco CMS itself.
Other sources
An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67288?
CVE-2025-67288 is considered a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2025-67288?
To fix CVE-2025-67288, upgrade Umbraco CMS to version 16.3.4 or later.
What type of attack does CVE-2025-67288 enable?
CVE-2025-67288 enables attackers to execute arbitrary code on the server by uploading a specially crafted PDF file.
Which versions of Umbraco CMS are affected by CVE-2025-67288?
CVE-2025-67288 affects Umbraco CMS versions up to and including 16.3.3.
Is CVE-2025-67288 a denial of service vulnerability?
No, CVE-2025-67288 is not a denial of service vulnerability; it is an arbitrary file upload vulnerability allowing code execution.