CVE-2025-46822 is an absolute path traversal vulnerability in the OsamaTaher/Java-springboot-codebase collection of Java and Spring Boot snippets, applications, and projects. Before commit c835c6f7799eacada4c0fc77e0816f250af01ad2, path validation was insufficient to prevent attacker-supplied absolute paths from being resolved or accessed. This can permit access to sensitive internal files outside the intended application-controlled directory.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains two Python proof-of-concept exploit scripts for CVE-2025-46822, an unauthenticated arbitrary file read vulnerability in a Spring Boot file API. The core issue described in the repo is that the application exposes /api/v1/files/{fileName} without authentication and resolves attacker-controlled file names in a way that permits absolute-path access outside the intended storage root. Repository structure is small and straightforward: two Python scripts, two README files, a license, and .gitignore. The main functional files are cve-2025-46822.py and CVE-2025-46822/CVE-2025-46822.py. Both scripts accept a target base URL and a file path, then issue an HTTP GET request to the vulnerable endpoint to retrieve file contents. The nested script URL-encodes the supplied absolute path before requesting /api/v1/files/{encoded_path}; the top-level script is more feature-rich, using colorized output, a default target of http://localhost:8080, optional output saving, verbose header display, and a --multiple mode that automatically probes a list of common sensitive files. Exploit capability is limited to information disclosure, not code execution. It can read arbitrary files accessible to the vulnerable application process, including OS files and application configuration/secrets such as /etc/passwd, .env, application.properties, and logs. Because the exploit performs direct retrieval rather than mere detection, it is a real exploit/POC rather than a scanner-only script. The implementation is operational but simple: no framework integration, no advanced evasion, and no customizable post-exploitation payload beyond file selection and local saving of retrieved content.
This repository contains a proof-of-concept exploit for CVE-2025-46822, an unauthenticated arbitrary file read vulnerability affecting Java Spring Boot applications that expose the /api/v1/files/{fileName} endpoint. The exploit is implemented in Python (CVE-2025-46822.py) and allows an attacker to specify a target URL and an absolute file path to retrieve files from the server's filesystem. The exploit works by sending a crafted HTTP GET request to the vulnerable endpoint, leveraging the application's improper handling of absolute paths. The README.md provides a detailed description of the vulnerability, usage instructions, and references. The repository is structured simply, with one exploit script and a README. The main fingerprintable endpoint is /api/v1/files/{fileName}, which is unauthenticated and allows arbitrary file access if the application is vulnerable.
10 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.