CVE-2026-25592 | Microsoft semantic-kernel up to 1.69.x SessionsPythonPlugin path traversal (GHSA-2ww3-72rp-wpp4 / EUVD-2026-5582)
A vulnerability classified as critical was found in Microsoft semantic-kernel up to 1.69.x. Impacted is an unknown function of the component SessionsPythonPlugin. The manipulation results in path traversal.
This vulnerability was named CVE-2026-25592. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.