Progress Telerik Document Processing Libraries Arbitrary File Export Vulnerability

Vulnerability

A vulnerability exists in Progress Telerik Document Processing Libraries, in versions prior to 2025 Q1 (2025.1.205), that allows the contents of a file from an arbitrary path to be exported to RTF format. This issue is present in libraries using .NET Standard 2.0.

Impact

Exploitation of this vulnerability could lead to unauthorized access to file contents, allowing them to be exported in RTF format.

Remediation

Users are advised to upgrade to Progress Telerik Document Processing Libraries version 2025 Q1 (2025.1.2xx). Those with a Telerik license can download the update from the Telerik Product Downloads page. For guidance on upgrading, refer to the Telerik Document Processing Upgrade Instructions.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.