IT

Tracker / CVE-2025-0526

CVE-2025-0526

Medium 5.4

In affected versions of Octopus Deploy it was possible to upload files to unexpected locations on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows.

Affected products and versions

octopus octopus_server · 2022.4.791 → 2024.3.13097
octopus octopus_server · 2024.4.401 → 2024.4.7091

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References