CVE-2025-29817: Microsoft Power Automate For Desktop
Medium severity, CVSS 5.7. EPSS: 0.9% chance of exploitation in the next 30 days.
Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network.
Affected products
- Microsoft Power Automate For Desktop: before 2.51.349.24355 (fixed in 2.51.349.24355)
Published 2025-04-15. Last modified 2026-06-17.