CVE-2025-66249

MEDIUM

Apache Livy 0.3.0-0.9.0 - Path Traversal

Title source: llm

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Livy. This issue affects Apache Livy: from 0.3.0 before 0.9.0. The vulnerability can only be exploited with non-default Apache Livy Server settings. If the configuration value "livy.file.local-dir-whitelist" is set to a non-default value, the directory checking can be bypassed. Users are recommended to upgrade to version 0.9.0, which fixes the issue.

Exploits (1)

nomisec WRITEUP
by sid6224 · poc
https://github.com/sid6224/CVE-2025-66249-POC

Scores

CVSS v3 6.3
EPSS 0.0007
EPSS Percentile 21.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-22
Status published
Products (3)
apache/livy 0.3.0 - 0.9.0
Apache Software Foundation/Apache Livy 0.3.0-incubating - 0.9.0-incubating
org.apache.livy/livy-server 0.3.0-incubating - 0.9.0-incubatingMaven
Published Mar 13, 2026
Tracked Since Mar 14, 2026