Skip to main content

External Control of File Name or Path

CVE-2025-26646

Severity High
Score 8/10

Summary

External control of "file name" or "path" in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network. This vulnerability affects Microsoft.Build.Tasks.Core versions 15.8.166 through 15.9.20, 16.0.461 through 16.11.0, 17.0.0 through 17.8.3, 17.9.5 through 17.10.4, 17.11.4 through 17.12.6, and 17.13.9.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • REQUIRED
  • LOW
  • HIGH
  • HIGH

CWE-73 - External Control of File Name or Path

The software allows user input to control or influence paths or file names that are used in filesystem operations.

Advisory Timeline

  • Published