CVE-2025-11842
C# vulnerability analysis and mitigation

Overview

A path traversal vulnerability (CVE-2025-11842) has been identified in Shazwazza Smidge versions up to 4.5.1. The vulnerability affects the Bundle Handler component, where manipulation of the Version argument can lead to path traversal attacks. The issue was disclosed in September 2025 and affects the core functionality of the Smidge library, which is a lightweight solution for CSS and JavaScript file management in Microsoft .NET applications (NVD, GitHub Release).

Technical details

The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory) and has received a CVSS v4.0 Base Score of 5.3 (Medium) with vector string CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N. The issue specifically involves the Bundle Handler component's handling of the Version parameter, which can be manipulated to achieve path traversal. Remote exploitation is possible with low attack complexity (NVD, VulDB).

Impact

The vulnerability can potentially be exploited to enumerate usernames on the web server and deplete available hard disk space, affecting system availability. The impact is particularly concerning as Smidge has over 10M downloads on NuGet and is integrated into several versions of the Umbraco CMS, including versions 10, 11, 12, and 13 (GitHub Vuln).

Mitigation and workarounds

The vulnerability has been patched in version 4.6.0. Organizations are strongly recommended to upgrade to this version. Additional mitigations include: ensuring correct permissions are assigned to web application user accounts, avoiding the use of TimestampCacheBuster in production environments, and disabling Developer Exception Page or detailed exceptions in production environments (GitHub Release).

Additional resources


SourceThis report was generated using AI

Related C# vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-55315CRITICAL9.9
  • C#C#
  • dotnet-runtime-8.0
NoYesOct 14, 2025
CVE-2025-54539CRITICAL9.8
  • C#C#
  • Apache.NMS.AMQP
NoYesOct 16, 2025
CVE-2025-11849MEDIUM6.4
  • JavaScriptJavaScript
  • Mammoth
NoYesOct 17, 2025
CVE-2025-11842MEDIUM5.3
  • C#C#
  • Smidge
NoYesOct 16, 2025
CVE-2025-55248MEDIUM4.8
  • C#C#
  • aspnetcore-runtime-dbg-8.0
NoYesOct 14, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management