CVE-2025-60722

Name
CVE-2025-60722
Description
Improper limitation of a pathname to a restricted directory ('path traversal') in OneDrive for Android allows an authorized attacker to elevate privileges over a network.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
secure@microsoft.com https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-60722

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:microsoft:onedrive:*:*:*:*:*:android:*:* onedrive >= None < 7.42

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
onedrive edge-community 2.5.9-r0 Duncan Bellamy <dunk@denkimushi.com> possibly vulnerable
onedrive edge-community 2.5.7-r0 Duncan Bellamy <dunk@denkimushi.com> possibly vulnerable
onedrive edge-community 2.5.6-r0 Duncan Bellamy <dunk@denkimushi.com> possibly vulnerable
onedrive edge-community 2.5.5-r0 Duncan Bellamy <dunk@denkimushi.com> possibly vulnerable
onedrive edge-community 2.5.4-r0 Duncan Bellamy <dunk@denkimushi.com> possibly vulnerable
onedrive edge-community 2.5.3-r1 Duncan Bellamy <dunk@denkimushi.com> possibly vulnerable
onedrive edge-community 2.5.3-r0 Duncan Bellamy <dunk@denkimushi.com> possibly vulnerable
onedrive 3.22-community 2.5.5-r0 Duncan Bellamy <dunk@denkimushi.com> possibly vulnerable
onedrive 3.22-community 2.5.3-r0 Duncan Bellamy <dunk@denkimushi.com> possibly vulnerable