CVE-2025-0525: Octopus Server

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

In affected versions of Octopus Server the preview import feature could be leveraged to identify the existence of a target file. This could provide an adversary with information that may aid in further attacks against the server.

Affected products

  • Octopus Octopus Server: from 2020.6.4592, before 2024.3.13007 (fixed in 2024.3.13007); from 2024.4.401, before 2024.4.6995 (fixed in 2024.4.6995)

Published 2025-02-11. Last modified 2026-06-17.