CVE-2025-49493 is an XML External Entity (XXE) injection vulnerability in Akamai CloudTest before version 60 2025.06.02 (build 12988). The issue allows file inclusion through unsafe processing of XML input with external entities enabled or insufficiently restricted. By supplying crafted XML containing external entity declarations, an attacker can cause the application to resolve local or other referenced resources during XML parsing.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository is a standalone Python proof-of-concept/operational exploit for CVE-2025-49493, an XXE issue in Akamai CloudTest affecting versions before 60 2025.06.02 (12988). The repository is small and centered on a single executable script, main.py, supported by documentation (README.md), dependency metadata (pyproject.toml, uv.lock), a Python version pin, and a sample targets.txt file. The exploit workflow in main.py is straightforward: it accepts a target list and an attacker-controlled XXE callback server, disables TLS verification warnings, creates a requests session with certificate verification disabled, fingerprints each target for Akamai CloudTest indicators, checks whether the SOAP endpoint /concerto/services/RepositoryService is reachable, and then attempts exploitation by sending a crafted SOAP/XML payload containing an external entity reference to the supplied callback host. The intended success condition is out-of-band interaction from the target to the attacker-controlled DNS/HTTP endpoint, allowing the operator to confirm XXE. Capabilities include batch processing of multiple targets, basic target validation, product fingerprinting via response content/headers, SOAP endpoint reachability checks, XXE payload delivery, colored/timestamped logging, and configurable request timeout. The exploit does not appear to include a post-exploitation payload such as a shell; instead it is focused on vulnerability verification and OOB-triggered XXE/SSRF-style interaction. Because it contains active exploitation logic rather than mere detection, it is best classified as an operational standalone exploit rather than a framework module. Notable implementation details visible from the provided content: the exploit path is hardcoded to /concerto/services/RepositoryService; the script uses requests.Session with verify=False; it looks for CloudTest-related strings such as 'Akamai CloudTest', 'concerto', 'CloudTest', and 'akamai'; and it expects the operator to monitor an external callback infrastructure such as Burp Collaborator, Interactsh, or a custom HTTP server. There is a minor metadata inconsistency in pyproject.toml where the project name references cve-2025-48827 instead of CVE-2025-49493, but the README and script header consistently describe the CloudTest XXE exploit.
This repository is a Python-based operational exploit for CVE-2025-49493, a critical XXE vulnerability in Akamai CloudTest versions before 60 2025.06.02 (12988). The exploit consists of a single main code file (main.py), a README with detailed usage and technical information, and supporting files for Python environment and dependencies. The exploit automates the process of identifying Akamai CloudTest instances, checking for the vulnerable SOAP endpoint (/concerto/services/RepositoryService), and sending a crafted XML payload containing an external entity. The attacker must provide a list of targets (targets.txt) and an XXE server (such as Burp Collaborator or Interactsh) to capture out-of-band requests. The exploit is capable of batch processing multiple targets, provides detailed logging, and robust error handling. The main attack vector is network-based, targeting exposed SOAP endpoints. The payload is a standard XXE vector embedded in a SOAP envelope, and successful exploitation can result in information disclosure, SSRF, DoS, or potentially RCE depending on server configuration. The repository is well-structured, with clear separation of code, documentation, and configuration files.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.