CVE-2025-60722
onedrive: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CVE-2025-60722)
mediumEPSS 0.8%
Affected
- microsoft/onedrive
lt *..7.42
Description
Improper limitation of a pathname to a restricted directory ('path traversal') in OneDrive for Android allows an authorized attacker to elevate privileges over a network.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
microsoftonedrive
7.42fixed from 7.42Metrics
Show all metrics
Severity
medium
70.07
no public PoC known
6.5
Published
2025-11-11 17:59 UTC
CWE-22
Weakness classes (CWE)
CWE-22Base
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
cwe.mitre.org →