CVE-2026-25592

CRITICAL

Nuget Microsoft.semantickernel.core < 1.70.0 - Path Traversal

Title source: rule
STIX 2.1

Description

Semantic Kernel is an SDK used to build, orchestrate, and deploy AI agents and multi-agent systems. Prior to 1.71.0, an Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the SessionsPythonPlugin. The problem has been fixed in Microsoft.SemanticKernel.Core version 1.71.0. As a mitigation, users can create a Function Invocation Filter which checks the arguments being passed to any calls to DownloadFileAsync  or UploadFileAsync and ensures the provided localFilePath is allow listed.

Scores

CVSS v3 9.9
EPSS 0.0007
EPSS Percentile 20.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (2)
nuget/Microsoft.SemanticKernel.Core 0 - 1.70.0NuGet
pypi/semantic-kernel 0 - 1.39.3PyPI
Published Feb 06, 2026
Tracked Since Feb 18, 2026