Executive brief
A vulnerability exists in the Telerik UI for ASP.NET AJAX library, a popular suite of components used to build web applications. The flaw is located in the spell-checking feature, where improper handling of user input could allow an attacker to access sensitive files on the server or trigger unauthorized network requests. This could lead to the exposure of confidential data or provide a foothold for further attacks on the internal network.
Technical details
A path traversal vulnerability (CWE-36) exists in the RadSpell component of Progress Telerik UI for ASP.NET AJAX. The spell check handler fails to properly validate the 'language' parameter provided in HTTP requests. An unauthenticated remote attacker can exploit this by supplying manipulated file paths, allowing them to influence server-side file resolution. This can lead to unauthorized reading of local files or the triggering of unintended server-side network requests (SSRF). The issue is resolved in version 2026.2.708 (2026 Q2 SP1) and later.
Affected products
- Progress Software Telerik UI for ASP.NET AJAX >= 2011.2.712, <= 2026.2.519
Timeline
- 2026-07-22: disclosed
- 2026-07-22: advisory
- 2026-07-22: patched