External Control of File Name or Path
CVE-2025-26646
Summary
External control of "file name" or "path" in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network. This vulnerability affects Microsoft.Build.Tasks.Core versions 15.8.166 through 15.9.20, 16.0.461 through 16.11.0, 17.0.0 through 17.8.3, 17.9.5 through 17.10.4, 17.11.4 through 17.12.6, and 17.13.9.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- REQUIRED
- LOW
- HIGH
- HIGH
CWE-73 - External Control of File Name or Path
The software allows user input to control or influence paths or file names that are used in filesystem operations.
References
Advisory Timeline
- Published