CVE-2025-29817: Microsoft Power Automate For Desktop

Medium severity, CVSS 5.7. EPSS: 0.9% chance of exploitation in the next 30 days.

Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network.

Affected products

  • Microsoft Power Automate For Desktop: before 2.51.349.24355 (fixed in 2.51.349.24355)

Published 2025-04-15. Last modified 2026-06-17.