Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-11152 | Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network. |
Tue, 08 Jul 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft power Automate For Desktop |
|
| CPEs | cpe:2.3:a:microsoft:power_automate_for_desktop:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Microsoft
Microsoft power Automate For Desktop |
Tue, 15 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Apr 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network. | |
| Title | Microsoft Power Automate Desktop Information Disclosure Vulnerability | |
| Weaknesses | CWE-427 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-02-13T19:32:52.416Z
Reserved: 2025-03-11T22:56:43.942Z
Link: CVE-2025-29817
Updated: 2025-04-15T17:52:56.653Z
Status : Analyzed
Published: 2025-04-15T17:15:48.873
Modified: 2025-07-08T16:26:03.653
Link: CVE-2025-29817
No data.
OpenCVE Enrichment
No data.
EUVD