
Security Advisory, June 3, 2025: Security Patch is now available
We recommend you upgrade to the latest patch

Who’s affected?
Versions affected:
-
Umbraco 15.0.0 - 15.4.1
Unsupported versions can be subject to the vulnerability, but will not receive a patch. We recommend upgrading to a supported major version.
How to fix the vulnerability
Patches are available for the latest minor of Umbraco 15. As we are looking at a patch upgrade, and the fix is straightforward, we expect the patch upgrade to only require minimal effort per project.
Instructions on patch availability and how to upgrade can be found in the release notes:
Automatic fix on Umbraco Cloud
All Umbraco Cloud sites running the latest minor version of a supported version are patched via the automated patch feature. The security patches will be rolled out to Umbraco Cloud today to ensure all sites have been fixed.
If a project is not running the latest minor version (15.4.x), the patch can be applied using the minor upgrade feature
ℹ️ Note that Umbraco Cloud also supports automated minor upgrades. This can be enabled on a per-project level and ensures you're always ready to receive the latest patch.
What we know about the vulnerability
Exploiting the vulnerability requires the user to be authenticated to the Umbraco backoffice. Via a manipulated API request it is possible to craft a payload that allows upload of files with extensions that are not allowed based on the website configuration.
For more details, please refer to the security advisory:
There are no indications that the vulnerabilities were discovered or exploited prior to the report.
Credit
We’d like to thank João Mendes (GitHub) from Devoteam Cyber Trust, Portugal for reporting the issues and responsible disclosure of details regarding the vulnerability.
Any questions?
If you have any questions or comments about this advisory, make sure to get in touch with us directly on the Security Advisories. Alternatively, you can reach out to the dedicated security email address listed at https://umbraco.com/security. Here you can also find information on how we handle security-related issues.
For direct communication related to security in Umbraco products, please sign up for the dedicated security mailing list.