Vulnerability Description
The Takes web framework's TkFiles take thru 2.0-SNAPSHOT fails to canonicalize HTTP request paths before resolving them against the filesystem. A remote attacker can include ../ sequences in the request path to escape the configured base directory and read arbitrary files from the host system.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Takes | Tkfiles | 2.0 |
Related Weaknesses (CWE)
References
- https://github.com/Xzzz111/public_cve_report/blob/main/CVE-2025-66905_report.mdExploitThird Party Advisory
- https://github.com/yegor256/takesProduct
FAQ
What is CVE-2025-66905?
CVE-2025-66905 is a vulnerability with a CVSS score of 7.5 (HIGH). The Takes web framework's TkFiles take thru 2.0-SNAPSHOT fails to canonicalize HTTP request paths before resolving them against the filesystem. A remote attacker can include ../ sequences in the reque...
How severe is CVE-2025-66905?
CVE-2025-66905 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-66905?
Check the references section above for vendor advisories and patch information. Affected products include: Takes Tkfiles.