Home
MEDIUM: 5.9 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:NDefault status
unaffected
2023.0.0 (custom) before 2025.3.14715
affected
2025.4.0 (custom) before 2025.4.10359
affected
Description
In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows.
Problem types
File Modification/Deletion Path Traversal
Product status
2023.0.0 (custom) before 2025.3.14715
2025.4.0 (custom) before 2025.4.10359
Credits
This vulnerability was found by oub3ll4
References
advisories.octopus.com/post/2026/sa2026-01