Advisories for Nuget/Microsoft.Build.Tasks.Core package

2025

Microsoft.Build.Tasks.Core .NET Spoofing Vulnerability

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 9.0.xxx and .NET 8.0.xxx SDK. This advisory also provides guidance on what developers can do to update their applications to address this vulnerability. A vulnerability exists in .NET SDK or MSBuild applications where external control of file name or path allows an unauthorized attacked to perform spoofing over a network.