External Control of File Name or Path Affecting microsoft.build.tasks.core package, versions [15.8.166,15.9.30)[16.0.461,16.11.6)[17.0.0,17.8.29)[17.9.5,17.10.29)[17.11.4,17.12.36)[17.13.9,17.13.26)[17.14.5,17.14.8)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DOTNET-MICROSOFTBUILDTASKSCORE-10123467
  • published14 May 2025
  • disclosed13 May 2025
  • creditUnknown

Introduced: 13 May 2025

NewCVE-2025-26646  (opens in a new tab)
CWE-73  (opens in a new tab)

How to fix?

Upgrade Microsoft.Build.Tasks.Core to version 15.9.30, 16.11.6, 17.8.29, 17.10.29, 17.12.36, 17.13.26, 17.14.8 or higher.

Overview

Microsoft.Build.Tasks.Core is a This package contains the Microsoft.Build.Tasks assembly which implements the commonly used tasks of MSBuild.

Affected versions of this package are vulnerable to External Control of File Name or Path due to the external control of file name or path. An attacker can spoof network identities by manipulating file paths or names used in the application.

Note: This vulnerability only affects projects that use the DownloadFile build task.

CVSS Base Scores

version 4.0
version 3.1