CVE-2025-0526

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Feb 11, 2025
CWE ID 22

Summary

CVE-2025-0526 is a vulnerability affecting Octopus Deploy. This issue allows an attacker to upload files to unintended locations on the host through an API endpoint. The vulnerability arises due to insufficient validation in the field, potentially enabling bypassing of anticipated workflows.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share