CVE-2025-60722: Microsoft OneDrive
Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.
Improper limitation of a pathname to a restricted directory ('path traversal') in OneDrive for Android allows an authorized attacker to elevate privileges over a network.
Affected products
- Microsoft OneDrive: before 7.42 (fixed in 7.42)
Published 2025-11-11. Last modified 2026-06-17.