CVE-2025-66249 is a path traversal vulnerability in Apache Livy Server (org.apache.livy:livy-server). It affects Apache Livy versions 0.3.0 through versions before 0.9.0. The issue stems from insufficient restriction of file path handling when validating access against a configured local directory whitelist. When the non-default configuration option "livy.file.local-dir-whitelist" is set, the directory checking logic can be bypassed, allowing pathname restrictions to be circumvented and enabling access outside the intended restricted directory set.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept and research bundle for CVE-2025-66249, a path traversal whitelist bypass in Apache Livy. It is not just documentation: it includes Dockerized vulnerable and fixed environments plus a vendored copy of Apache Livy 0.8.0 source to support analysis and reproduction. Core exploit capability: an authenticated user can submit a Livy session or job that references a crafted local file path/URI such as `file:///opt/safe-data/../sensitive/secret.txt`. In affected Livy versions, the whitelist check compares the raw path string with `startsWith()` before normalization, so a path beginning with the whitelisted prefix but resolving outside it is accepted. The result is unauthorized local file access on the Livy server host, limited by the Livy process's filesystem permissions. Repository structure: - Top-level `README.md`: detailed vulnerability write-up, affected versions, root cause, fix diff, and references. - `docker/vulnerable/`: builds a reproducible Livy 0.8.0 environment with `livy.file.local-dir-whitelist=/opt/safe-data`, exposes port 8998, and creates a target secret file at `/opt/sensitive/secret.txt`. - `docker/fixed/`: same setup using Livy 0.9.0-incubating to demonstrate remediation. - `livy-0.8.0/`: substantial upstream Apache Livy source tree, including Java/Scala client code, configs, scripts, tests, and Docker dev assets. This is mainly context/supporting source, not custom exploit code. Notable code behavior from the included Livy client implementation: - HTTP/HTTPS client support via `HttpClientFactory` and `LivyConnection`. - REST interaction with `/sessions`, job submission, file/jar upload, and add-file/add-jar endpoints. - The `addFile(URI)` and related resource APIs are especially relevant because the vulnerability concerns server-side validation of local file URIs. The exploit is best classified as a network-based authenticated path traversal PoC rather than a weaponized exploit. No shell, RCE payload, or persistence mechanism is included; the demonstrated impact is arbitrary local file reference/read exposure through Livy's session/job submission workflow.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.