CVE-2025-66905

The Takes web framework's TkFiles take thru 2.0-SNAPSHOT fails to canonicalize HTTP request paths before resolving them against the filesystem. A remote attacker can include ../ sequences in the request path to escape the configured base directory and read arbitrary files from the host system.
Configurations

Configuration 1 (hide)

cpe:2.3:a:takes:tkfiles:2.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-19 16:15

Updated : 2026-01-06 15:52


NVD link : CVE-2025-66905

Mitre link : CVE-2025-66905

CVE.ORG link : CVE-2025-66905


JSON object : View

Products Affected

takes

  • tkfiles
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')